Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2017:2952-1

Опубликовано: 08 нояб. 2017
Источник: suse-cvrf

Описание

Security update for poppler

This update for poppler fixes the following issues:

This security issue was fixed:

  • CVE-2017-14517: Prevent NULL Pointer dereference in the XRef::parseEntry() function via a crafted PDF document (bsc#1059066).
  • CVE-2017-14518: Remedy a floating point exception in isImageInterpolationRequired() that could have been exploited using a specially crafted PDF document. (bsc#1059101)
  • CVE-2017-14520: Remedy a floating point exception in Splash::scaleImageYuXd() that could have been exploited using a specially crafted PDF document. (bsc#1059155)
  • CVE-2017-14977: Fixed a NULL pointer dereference vulnerability in the FoFiTrueType::getCFFBlock() function in FoFiTrueType.cc that occurred due to lack of validation of a table pointer, which allows an attacker to launch a denial of service attack. (bsc#1061265)

Список пакетов

SUSE Linux Enterprise Desktop 12 SP2
libpoppler44-0.24.4-14.13.1
SUSE Linux Enterprise Server 12 SP2
libpoppler44-0.24.4-14.13.1
SUSE Linux Enterprise Server for Raspberry Pi 12 SP2
libpoppler44-0.24.4-14.13.1
SUSE Linux Enterprise Server for SAP Applications 12 SP2
libpoppler44-0.24.4-14.13.1
SUSE Linux Enterprise Software Development Kit 12 SP3
libpoppler44-0.24.4-14.13.1

Описание

In Poppler 0.59.0, a NULL Pointer Dereference exists in the XRef::parseEntry() function in XRef.cc via a crafted PDF document.


Затронутые продукты
SUSE Linux Enterprise Desktop 12 SP2:libpoppler44-0.24.4-14.13.1
SUSE Linux Enterprise Server 12 SP2:libpoppler44-0.24.4-14.13.1
SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpoppler44-0.24.4-14.13.1
SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpoppler44-0.24.4-14.13.1

Ссылки

Описание

In Poppler 0.59.0, a floating point exception exists in the isImageInterpolationRequired() function in Splash.cc via a crafted PDF document.


Затронутые продукты
SUSE Linux Enterprise Desktop 12 SP2:libpoppler44-0.24.4-14.13.1
SUSE Linux Enterprise Server 12 SP2:libpoppler44-0.24.4-14.13.1
SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpoppler44-0.24.4-14.13.1
SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpoppler44-0.24.4-14.13.1

Ссылки

Описание

In Poppler 0.59.0, a floating point exception occurs in Splash::scaleImageYuXd() in Splash.cc, which may lead to a potential attack when handling malicious PDF files.


Затронутые продукты
SUSE Linux Enterprise Desktop 12 SP2:libpoppler44-0.24.4-14.13.1
SUSE Linux Enterprise Server 12 SP2:libpoppler44-0.24.4-14.13.1
SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpoppler44-0.24.4-14.13.1
SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpoppler44-0.24.4-14.13.1

Ссылки

Описание

The FoFiTrueType::getCFFBlock function in FoFiTrueType.cc in Poppler 0.59.0 has a NULL pointer dereference vulnerability due to lack of validation of a table pointer, which allows an attacker to launch a denial of service attack.


Затронутые продукты
SUSE Linux Enterprise Desktop 12 SP2:libpoppler44-0.24.4-14.13.1
SUSE Linux Enterprise Server 12 SP2:libpoppler44-0.24.4-14.13.1
SUSE Linux Enterprise Server for Raspberry Pi 12 SP2:libpoppler44-0.24.4-14.13.1
SUSE Linux Enterprise Server for SAP Applications 12 SP2:libpoppler44-0.24.4-14.13.1

Ссылки
Уязвимость SUSE-SU-2017:2952-1