Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-0128

Опубликовано: 06 янв. 2026
Источник: oracle-oval
Платформа: Oracle Linux 10

Описание

ELSA-2026-0128: poppler security update (MODERATE)

[24.02.0-7]

  • Check bitmap in combine()
  • Resolves: RHEL-131783, RHEL-131782

Обновленные пакеты

Oracle Linux 10

Oracle Linux aarch64

poppler

24.02.0-7.el10_1

poppler-cpp

24.02.0-7.el10_1

poppler-glib

24.02.0-7.el10_1

poppler-qt6

24.02.0-7.el10_1

poppler-utils

24.02.0-7.el10_1

poppler-cpp-devel

24.02.0-7.el10_1

poppler-devel

24.02.0-7.el10_1

poppler-glib-devel

24.02.0-7.el10_1

poppler-glib-doc

24.02.0-7.el10_1

poppler-qt6-devel

24.02.0-7.el10_1

Oracle Linux x86_64

poppler

24.02.0-7.el10_1

poppler-cpp

24.02.0-7.el10_1

poppler-glib

24.02.0-7.el10_1

poppler-qt6

24.02.0-7.el10_1

poppler-utils

24.02.0-7.el10_1

poppler-cpp-devel

24.02.0-7.el10_1

poppler-devel

24.02.0-7.el10_1

poppler-glib-devel

24.02.0-7.el10_1

poppler-glib-doc

24.02.0-7.el10_1

poppler-qt6-devel

24.02.0-7.el10_1

Связанные CVE

Связанные уязвимости

CVSS3: 4
ubuntu
10 месяцев назад

Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the JBIG2Bitmap::combine function in JBIG2Stream.cc because of a misplaced isOk check.

CVSS3: 4
redhat
10 месяцев назад

Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the JBIG2Bitmap::combine function in JBIG2Stream.cc because of a misplaced isOk check.

CVSS3: 4
nvd
10 месяцев назад

Poppler before 25.04.0 allows crafted input files to trigger out-of-bounds reads in the JBIG2Bitmap::combine function in JBIG2Stream.cc because of a misplaced isOk check.

CVSS3: 4
debian
10 месяцев назад

Poppler before 25.04.0 allows crafted input files to trigger out-of-bo ...

rocky
около 1 месяца назад

Moderate: poppler security update