Описание
ELSA-2026-30044: poppler security update (IMPORTANT)
[0.26.5-43.0.1.el7.1]
- Fix for CVE-2026-10118 [Orabug: 39637155]
[0.26.5-43.el7_9.1]
- Handle bytestring representation of named dests
- Resolves: #1857678
Обновленные пакеты
Oracle Linux 7
Oracle Linux x86_64
poppler
0.26.5-43.0.1.el7.1
poppler-cpp
0.26.5-43.0.1.el7.1
poppler-cpp-devel
0.26.5-43.0.1.el7.1
poppler-demos
0.26.5-43.0.1.el7.1
poppler-devel
0.26.5-43.0.1.el7.1
poppler-glib
0.26.5-43.0.1.el7.1
poppler-glib-devel
0.26.5-43.0.1.el7.1
poppler-qt
0.26.5-43.0.1.el7.1
poppler-qt-devel
0.26.5-43.0.1.el7.1
poppler-utils
0.26.5-43.0.1.el7.1
Связанные CVE
Связанные уязвимости
A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered, triggers an integer overflow in the `tilingPatternFill` function. This overflow leads to an undersized heap memory allocation, allowing a subsequent out-of-bounds write. Successful exploitation could result in arbitrary code execution, information disclosure, or denial of service within the context of the application processing the PDF.
A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered, triggers an integer overflow in the `tilingPatternFill` function. This overflow leads to an undersized heap memory allocation, allowing a subsequent out-of-bounds write. Successful exploitation could result in arbitrary code execution, information disclosure, or denial of service within the context of the application processing the PDF.
A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered, triggers an integer overflow in the `tilingPatternFill` function. This overflow leads to an undersized heap memory allocation, allowing a subsequent out-of-bounds write. Successful exploitation could result in arbitrary code execution, information disclosure, or denial of service within the context of the application processing the PDF.
A flaw was found in Poppler's Splash backend. A remote attacker could ...