Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2022:1316-1

Опубликовано: 22 апр. 2022
Источник: suse-cvrf

Описание

Security update for podofo

This update for podofo fixes the following issues:

  • CVE-2019-20093: Fixed an invalid memory access that could cause an application crash (bsc#1159921).

Список пакетов

openSUSE Leap 15.3
libpodofo-devel-0.9.6-150300.3.3.1
libpodofo0_9_6-0.9.6-150300.3.3.1
podofo-0.9.6-150300.3.3.1

Описание

The PoDoFo::PdfVariant::DelayedLoad function in PdfVariant.h in PoDoFo 0.9.6 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file, because of ImageExtractor.cpp.


Затронутые продукты
openSUSE Leap 15.3:libpodofo-devel-0.9.6-150300.3.3.1
openSUSE Leap 15.3:libpodofo0_9_6-0.9.6-150300.3.3.1
openSUSE Leap 15.3:podofo-0.9.6-150300.3.3.1

Ссылки