Описание
Security update for podofo
This update for podofo fixes the following issues:
- CVE-2019-20093: Fixed an invalid memory access that could cause an application crash (bsc#1159921).
Список пакетов
openSUSE Leap 15.3
libpodofo-devel-0.9.6-150300.3.3.1
libpodofo0_9_6-0.9.6-150300.3.3.1
podofo-0.9.6-150300.3.3.1
Ссылки
- Link for SUSE-SU-2022:1316-1
- E-Mail link for SUSE-SU-2022:1316-1
- SUSE Security Ratings
- SUSE Bug 1159921
- SUSE CVE CVE-2019-20093 page
Описание
The PoDoFo::PdfVariant::DelayedLoad function in PdfVariant.h in PoDoFo 0.9.6 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file, because of ImageExtractor.cpp.
Затронутые продукты
openSUSE Leap 15.3:libpodofo-devel-0.9.6-150300.3.3.1
openSUSE Leap 15.3:libpodofo0_9_6-0.9.6-150300.3.3.1
openSUSE Leap 15.3:podofo-0.9.6-150300.3.3.1
Ссылки
- CVE-2019-20093
- SUSE Bug 1159921