Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2024-2979

Опубликовано: 23 мая 2024
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2024-2979: poppler security update (MODERATE)

[21.01.0-11]

  • Fix crashes in FoFiType1C
  • Rebuild for inclusion of poppler-glib-doc in CRB
  • Resolves: RHEL-4255, RHEL-4273

[21.01.0-10]

  • Check XRef's Catalog for being a Dict
  • Resolves: #2189816

[20.11.0-9]

  • Check isDict before calling getDict 2
  • Resolves: #2189837

[20.11.0-8]

  • Check isDict before calling getDict
  • Resolves: #2189823

[20.11.0-7]

  • Don't crash in broken documents
  • Resolves: #2189844

[20.11.0-6]

  • Check for overflow when computing number of symbols
  • in JBIG2 text region
  • Resolves: #2126361

[20.11.0-5]

  • Don't run out of file for Hints
  • Rebuild for #2096452
  • Resolves: #2090969, #2096452

[20.11.0-4]

  • Fix opening files with streams with wrong generations
  • Resolves: #2002575

[20.11.0-3]

  • Fix crash when processing dates of embedded files
  • Resolves: #1981108

[20.11.0-2]

  • Improve python3 build dependency
  • Resolves: #1896335

[20.11.0-1]

  • Rebase poppler to 20.11.0
  • Modify/remove patches as needed
  • Resolves: #1644423

[0.66.0-27]

  • Fix crash on broken file in tilingPatternFill()
  • Resolves: #1801341

[0.66.0-26]

  • Coverity scan related fixes
  • Related: #1618766

[0.66.0-25]

  • Check whether input is RGB in PSOutputDev::checkPageSlice()
  • also when using '-optimizecolorspace' flag
  • Resolves: #1697576

[0.66.0-24]

  • Check whether input is RGB in PSOutputDev::checkPageSlice()
  • Resolves: #1697576

[0.66.0-23]

  • Ignore dict Length if it is broken
  • Resolves: #1733027

[0.66.0-22]

  • Fail gracefully if not all components of JPEG2000Stream
  • have the same size
  • Resolves: #1723505

[0.66.0-21]

  • Implement crypto functions using NSS
  • Resolves: #1618766

[0.66.0-20]

  • Fix stack overflow on broken file
  • Resolves: #1691887

[0.66.0-19]

  • Constrain number of cycles in rescale filter
  • Compute correct coverage values for box filter
  • Resolves: #1688418

[0.66.0-18]

  • Fix possible crash on broken files in ImageStream::getLine()
  • Resolves: #1685268

[0.66.0-17]

  • Check Catalog from XRef for being a Dict
  • Resolves: #1677347

[0.66.0-16]

  • Move the fileSpec.dictLookup call inside fileSpec.isDict if
  • Resolves: #1677028

[0.66.0-15]

  • Do not try to construct invalid rich media annotation assets
  • Resolves: #1677025

[0.66.0-14]

  • Defend against requests for negative XRef indices
  • Resolves: #1673699

[0.66.0-13]

  • Do not try to parse into unallocated XRef entry
  • Resolves: #1677057

[0.66.0-12]

  • Avoid global display profile state becoming an uncontrolled
  • memory leak
  • Resolves: #1646552

[0.66.0-11]

  • Fix tiling patterns when pattern cell is too far
  • Resolves: #1644094

[0.66.0-10]

  • Check for valid file name of embedded file
  • Resolves: #1649453

[0.66.0-9]

  • Check for valid embedded file before trying to save it
  • Resolves: #1649443

[0.66.0-8]

  • Check for stream before calling stream methods
  • when saving an embedded file
  • Resolves: #1649438

[0.66.0-7]

  • Fix crash on missing embedded file
  • Resolves: #1649460

[0.66.0-6]

  • Avoid cycles in PDF parsing
  • Resolves: #1626623

[0.66.0-5]

  • Fix crash when accessing list of selections
  • Resolves: #1638712

[0.66.0-4]

  • Fix important issues found by covscan
  • Resolves: #1602662

[0.66.0-3]

  • Fix BuildRequires for /usr/bin/python3
  • Resolves: #1615561

[0.66.0-2]

  • Fix crash when Object has negative number (CVE-2018-13988)
  • Resolves: #1607463

[0.66.0-1]

  • Rebase poppler to 0.66.0
  • Resolves: #1600553

[0.62.0-4]

  • Drop reversion of removal of Qt4 frontend

[0.62.0-3]

  • Fix infinite recursion (CVE-2017-18267)
  • Resolves: #1578779

[0.62.0-2]

  • Fix building of poppler with python3 only
  • Resolves: #1580849

[0.62.0-1]

  • new upstream release

[0.61.1-2]

[0.61.1-1]

  • new upstream release

[0.61.0-1]

  • new upstream release

[0.60.1-2]

  • -qt5: drop hard-coded versioned dependency

[0.60.0-1]

  • new upstream release

[0.59.0-2]

  • Resolves: rhbz#1494583 CVE-2017-14520

[0.59.0-1]

  • new upstream release

[0.57.0-1]

  • new upstream release

[0.56.0-4]

[0.56.0-3]

[0.56.0-2]

  • Resolves: rhbz#1459067 CVE-2017-7515 CVE-2017-9775 CVE-2017-9776 CVE-2017-9865

[0.56.0-1]

  • new upstream release

[0.55.0-2]

  • Resolves: rhbz#1456828 CVE-2017-7511 Null pointer deference

[0.55.0-1]

  • new upstream release

[0.53.0-1]

  • new upstream release

[0.52.0-1]

  • new upstream release

[0.51.0-2]

[0.51.0-1]

  • new upstream release

[0.50.0-1]

  • new upstream release

[0.49.0-1]

  • new upstream release

[0.48.0-1]

  • Update to 0.48.0
  • Resolves: #1359555

[0.45.0-2]

  • Don't crash when calling cmsGetColorSpace()
  • Resolves: #1363669

[0.45.0-1]

  • Update to 0.45.0
  • Resolves: #1338421

[0.43.0-2]

  • Restore the current position of char also in output device
  • Related: #1352717

[0.43.0-1]

  • Update to 0.43.0
  • Resolves: #1318462

[0.41.0-1]

  • Update to 0.41.0
  • Resolves: #1309145

[0.40.0-2]

[0.40.0-1]

  • Update to 0.40.0
  • Resolves: #1251781

[0.34.0-1]

  • Update to 0.34.0
  • Resolves: #1241305

[0.33.0-2]

[0.33.0-1]

  • Update to 0.33.0
  • Resolves: #1190427

[0.30.0-5]

  • Rebuilt for GCC 5 C++11 ABI change

[0.30.0-4]

  • Respect orientation when selecting words
  • Resolves: #1185007

[0.30.0-3]

[0.30.0-2]

  • Use libopenjpeg2 instead of libopenjpeg

[0.30.0-1]

  • Update to 0.30.0
  • Resolves: #1171056

[0.28.1-3]

  • Revert previous commit (It needs poppler-0.30.0)

[0.28.1-2]

  • Use libopenjpeg2 instead of libopenjpeg

[0.28.1-1]

  • Update to 0.28.1
  • Resolves: #1147443

[0.26.4-1]

  • Update to 0.26.4

[0.26.3-2]

[0.26.3-1]

  • Update to 0.26.3

[0.26.2-2]

  • Rebuilt for gobject-introspection 1.41.4

[0.26.2-1]

  • Update to 0.26.2

[0.26.0-2]

[0.26.0-1]

  • Update to 0.26.0

[0.24.3-3]

  • Use correct format string
  • Resolves: #1048202

[0.24.3-2]

  • rebuild (qt5 qreal/arm)

[0.24.3-1]

  • Update to 0.24.3
  • Resolves: #1023712

[0.24.2-4]

  • fix mocversiongrep configure checks (so Qt 5.2 works)
  • %configure --disable-silent-rules

[0.24.2-3]

  • undo ExcludeArch: ppc ppc64 (qt5-qtbase-5.1.1-6+ fixed)

[0.24.2-2]

  • -qt5: ExcludeArch: ppc ppc64 (f20, hopefully temporary)

[0.24.2-1]

  • Update to 0.24.2

[0.24.1-2]

  • Don't convert pdftohtml.1 to UTF-8, it is already UTF-8

[0.24.1-1]

  • Update to 0.24.1

[0.24.0-2]

  • Fix Qt5 requirements

[0.24.0-1]

  • Update to 0.24.0

[0.22.5-2]

[0.22.5-1]

  • Update to 0.22.5

[0.22.1-5]

  • Switch from LCMS to LCMS2
  • Resolves: #975465

[0.22.1-4]

  • Fix changelog dates

[0.22.1-3]

  • Enable generating of TIFF files by pdftoppm

[0.22.1-2]

  • Fix man pages of pdftops and pdfseparate

[0.22.1-1]

  • Update to 0.22.1

[0.22.0-3]

[0.22.0-2]

  • -demos: omit extraneous (and broken) dep

[0.22.0-1]

  • Update to 0.22.0

[0.20.2-9]

  • Move poppler-glib-demo to new sub-package demos
  • Resolves: #872338

[0.20.2-8]

  • Add references to corresponding bugs for poppler-0.20.3-5.patch

[0.20.2-7]

  • Add missing hunk to patch poppler-0.20.3-5.patch

[0.20.2-6]

  • Backport most of the changes from poppler-0.20.3 - poppler-0.20.5
  • (those which doesn't change API or ABI and are important)
  • See poppler-0.20.3-5.patch for detailed list of included commits

[0.20.2-5]

  • Remove unused patch

[0.20.2-4]

  • Update License field

[0.20.2-3]

  • Fix conversion to ps when having multiple strips

[0.20.2-2]

  • Make sure xScale and yScale are always initialized
  • Resolves: #840515

[0.20.2-1]

  • Update to 0.20.2

[0.20.1-3]

  • Try empty string instead of NULL as password if needed
  • Resolves: #845578

[0.20.1-2]

[0.20.1-1]

  • Update to 0.20.1
  • license is 'GPLv2 or GPLv3' from poppler-0.20.0 on (based off xpdf-3.03)

[0.20.0-1]

  • Update to 0.20.0

[0.18.4-3]

  • Backport of a patch which sets mask matrix before drawing an image with a mask
  • Resolves: #817378

[0.18.4-2]

  • Rebuilt for c++ ABI breakage

[0.18.4-1]

  • 0.18.4

[0.18.3-3]

  • rebuild (openjpeg)

[0.18.3-2]

  • -devel: don't own all headers

[0.18.3-1]

  • 0.18.3

[0.18.2-2]

[0.18.2-1]

  • Update to 0.18.2
  • Remove upstreamed patches

[0.18.1-3]

  • Rebuild for new libpng

[0.18.1-2]

  • poppler-glib.pc pkgconfig file broken (#749898)
  • %check: verify pkgconfig sanity

[0.18.1-1]

  • Update to 0.18.1
  • pkgconfig-style deps
  • tighten deps with %_isa

[0.18.0-2]

  • rebuild

[0.18.0-1]

  • Update to 0.18.0

[0.17.3-2]

  • Don't include pdfextract and pdfmerge in resulting packages for now
  • since they conflict with packages pdfmerge and mupdf (#740906)

[0.17.3-1]

  • Update to 0.17.3

[0.17.0-2]

  • Fix a problem with freeing of memory in PreScanOutputDev (#730941)

[0.17.0-1]

  • Update to 0.17.0

[0.16.7-1]

  • 0.16.7

[0.16.6-2]

  • Drop dependency on gtk-doc (#604412)

[0.16.6-1]

  • Update to 0.16.6

[0.16.5-1]

  • Update to 0.16.5

[0.16.4-1]

  • Update to 0.16.4

[0.16.3-2]

  • Update to 0.16.3

[0.16.3-1]

  • Update to 0.16.3

[0.16.2-2]

[0.16.2-1]

  • Update to 0.16.2

[0.16.0-3]

  • drop qt3 bindings
  • rename -qt4 -> -qt

[0.16.0-2]

  • rebuild (openjpeg)

[0.16.0-1]

  • 0.16.0

[0.15.3-1]

  • Update to 0.15.3

[0.15.1-1]

  • Update to 0.15.1
  • Remove CVE-2010-3702, 3703 and 3704 patches (they are already in 0.15.1)

[0.15.0-5]

  • Add poppler-0.15.0-CVE-2010-3702.patch (Properly initialize parser)
  • Add poppler-0.15.0-CVE-2010-3703.patch (Properly initialize stack)
  • Add poppler-0.15.0-CVE-2010-3704.patch (Fix crash in broken pdf (code < 0))
  • Resolves: #639861
  • Wed Sep 29 2010 jkeating - 0.15.0-4
  • Rebuilt for gcc bug 634757

[0.15.0-3]

  • Remove explicit requirement of gobject-introspection

[0.15.0-2]

  • Move requirement of gobject-introspection to glib sub-package

[0.15.0-1]

  • Update to 0.15.0
  • Enable introspection

[0.14.3-1]

  • Update to 0.14.3

[0.14.2-1]

  • Update to 0.14.2
  • Remove poppler-0.12.1-objstream.patch

[0.14.1-1]

  • Update to 0.14.1
  • Don't apply poppler-0.12.1-objstream.patch, it is not needed anymore

[0.14.0-1]

  • Update to 0.14.0

[0.13.4-1]

  • poppler-0.13.4

[0.13.3-2]

  • Update 'sources' file
  • Add BuildRequires 'gettext-devel'

[0.13.3-1]

  • poppler-0.13.3

[0.12.4-2]

  • Fix showing of radio buttons (#480868)

[0.12.4-1]

  • popper-0.12.4

[0.12.3-9]

  • Fix downscaling of rotated pages (#563353)

[0.12.3-8]

  • Get current FcConfig before using it (#533992)

[0.12.3-7]

  • use alternative/upstream downscale patch (#556549, fdo#5589)

[0.12.3-6]

  • Add dependency on poppler-data (#553991)

[0.12.3-5]

  • cairo backend, scale images correctly (#556549, fdo#5589)

[0.12.3-4]

  • Sanitize versioned Obsoletes/Provides

[0.12.3-3]

  • Correct permissions of goo/GooTimer.h
  • Convert pdftohtml.1 to utf8
  • Make the pdftohtml's Provides/Obsoletes versioned

[0.12.3-1]

  • poppler-0.12.3

[0.12.2-1]

  • poppler-0.12.2

[0.12.1-3]

  • CVE-2009-3607 poppler: create_surface_from_thumbnail_data integer overflow (#526924)

[0.12.1-1]

  • poppler-0.12.1
  • deprecate xpdf/pdftohtml Conflicts/Obsoletes

[0.12.0-1]

  • Update to 0.12.0

[0.11.3-1]

  • Update to 0.11.3

[0.11.2-1]

  • Update to 0.11.2

[0.11.1-3]

[0.11.1-2]

  • omit poppler-data (#507675)

[0.11.1-1]

  • poppler-0.11.1

[0.11.0-6]

  • reduce lib deps in qt/qt4 pkg-config support

[0.11.0-5]

  • --enable-libjpeg
  • (explicitly) --disable-zlib

[0.11.0-3]

  • --enable-libopenjpeg, --disable-zlib

[0.11.0-2]

  • update changelog
  • track sonames

[0.11.0-1]

  • Update to 0.11.0

[0.10.5-1]

  • Update to 0.10.5

[0.10.4-2]

[0.10.4-1]

  • Update to 0.10.4

[0.10.3-2]

  • add needed scriptlets
  • nuke rpaths

[0.10.3-1]

  • Update to 0.10.3

[0.10.2-1]

  • Update to 0.10.2

[0.10.1-1]

  • Update to 0.10.1 and -data 0.2.1

[0.8.7-2]

  • cleanup qt3 hack
  • %description cosmetics

[0.8.7-1]

  • Update to 0.8.7

[0.8.6-1]

  • Update to 0.8.6

[0.8.5-1]

  • Update to 0.8.5

[0.8.3-1]

  • Update to 0.8.3

[0.8.1-1]

  • Update to 0.8.1

[0.8.0-3]

  • poppler-0.8.0-ocg-crash.patch: Fix a crash when no optional content groups are defined.
  • Mangle configure to account for the new directory for qt3 libs.
  • Fix grammar in %description.

[0.8.0-2]

  • -qt-devel: Requires: qt3-devel

[0.8.0-1]

  • Update to 0.8.0

[0.7.3-1]

  • Update to 0.7.3

[0.7.2-1]

  • Update to 0.7.2

[0.7.1-1]

  • Update to 0.7.1

[0.7.0-1]

  • Update to 0.7.0

[0.6.4-4]

  • Autorebuild for GCC 4.3

[0.6.4-3]

  • apply ObjStream patch (#433090)

[0.6.4-2]

  • Add some required inter-subpackge deps

[0.6.4-1]

  • Update to 0.6.4
  • Split off poppler-glib

[0.6.2-3]

  • Fix the qt3 checks some more

[0.6.2-2]

  • package xpdf headers in poppler-devel (Jindrich Novy)
  • Fix qt3 detection (Denis Leroy)

[0.6.2-1]

  • Update to 0.6.2

[0.6-2]

  • include qt4 wrapper

[0.6-1]

  • Update to 0.6

[0.5.91-2]

  • Remove debug spew

[0.5.91-1]

  • Update to 0.5.91

[0.5.9-2]

  • Update the license field

[0.5.9-1]

  • Update to 0.5.9

[0.5.4-7]

  • fix it so the qt pkgconfig/.so aren't in the main poppler-devel

[0.5.4-5]

  • Include epoch in the Provides/Obsoletes for xpdf-utils

[0.5.4-4]

  • Add Provides/Obsoletes for xpdf-utils (#219033)

[0.5.4-3]

  • drop hard-wired: Req: gtk2
  • --disable-static
  • enable qt wrapper
  • -devel: Requires: pkgconfig

[0.5.4-2]

  • rebuilt for unwind info generation, broken in gcc-4.1.1-21

[0.5.4-1.fc6]

  • Rebase to 0.5.4, drop poppler-0.5.3-libs.patch, fixes #205813,

[0.5.3-3.fc6]

  • Move .so to -devel (#203637).

[0.5.3-2.fc6]

  • link against fontconfig (see bug 202256)

[0.5.3-1.1]

  • rebuild

[0.5.3-1]

  • Update to 0.5.3.

[0.5.2-1]

  • Update to 0.5.2.

[0.5.1-2]

  • Rebuild the get rid of old soname dependency.

[0.5.1-1]

  • Update to version 0.5.1.

[0.5.0-4.2]

  • bump again for double-long bug on ppc(64)

[0.5.0-4.1]

  • rebuilt for new gcc4.1 snapshot and glibc changes

[0.5.0-4]

  • change xpdf conflict version to be <= instead of <

[0.5.0-3]

  • update conflicts: xpdf line to be versioned

[0.5.0-2.0]

  • Update to 0.5.0 and add poppler-utils subpackage.
  • Flesh out poppler-utils subpackage.
  • rebuilt

[0.4.2-1]

  • Update to 0.4.2 and disable splash backend so we don't build it.

[0.4.1-2]

  • Rebuild

[0.4.1-1]

  • Update to 0.4.1

[0.4.0-2]

  • Bump release and rebuild.

[0.4.0-1]

  • Update to 0.4.0

[0.3.3-2]

  • Rebuild to pick up new cairo soname.

[0.3.3-1]

  • Update to 0.3.3 and change to build cairo backend.

[0.3.2-1]

  • Update to 0.3.2

[0.3.1]

  • Update to 0.3.1

[0.3.0]

  • Update to 0.3.0
  • remove empty post/postun scripts

[0.2.0-1]

  • Update to 0.2.0

[0.1.2-1]

  • Update to 0.1.2
  • Use tar.gz because there are not bz of poppler

[0.1.1-1]

  • Initial build

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

poppler

20.11.0-11.el8

poppler-cpp

20.11.0-11.el8

poppler-cpp-devel

20.11.0-11.el8

poppler-devel

20.11.0-11.el8

poppler-glib

20.11.0-11.el8

poppler-glib-devel

20.11.0-11.el8

poppler-glib-doc

20.11.0-11.el8

poppler-qt5

20.11.0-11.el8

poppler-qt5-devel

20.11.0-11.el8

poppler-utils

20.11.0-11.el8

Oracle Linux x86_64

poppler

20.11.0-11.el8

poppler-cpp

20.11.0-11.el8

poppler-cpp-devel

20.11.0-11.el8

poppler-devel

20.11.0-11.el8

poppler-glib

20.11.0-11.el8

poppler-glib-devel

20.11.0-11.el8

poppler-glib-doc

20.11.0-11.el8

poppler-qt5

20.11.0-11.el8

poppler-qt5-devel

20.11.0-11.el8

poppler-utils

20.11.0-11.el8

Связанные CVE

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 2 лет назад

An issue was discovered in freedesktop poppler version 20.12.1, allows remote attackers to cause a denial of service (DoS) via crafted .pdf file to FoFiType1C::convertToType1 function.

CVSS3: 5.5
redhat
около 2 лет назад

An issue was discovered in freedesktop poppler version 20.12.1, allows remote attackers to cause a denial of service (DoS) via crafted .pdf file to FoFiType1C::convertToType1 function.

CVSS3: 5.5
nvd
около 2 лет назад

An issue was discovered in freedesktop poppler version 20.12.1, allows remote attackers to cause a denial of service (DoS) via crafted .pdf file to FoFiType1C::convertToType1 function.

CVSS3: 5.5
debian
около 2 лет назад

An issue was discovered in freedesktop poppler version 20.12.1, allows ...

rocky
3 месяца назад

Moderate: poppler security update