Описание
Security update for podofo
This update for podofo fixes the following issues:
- CVE-2019-20093: Fixed an invalid memory access that could cause an application crash (bsc#1159921).
Список пакетов
SUSE Linux Enterprise Software Development Kit 12 SP5
libpodofo-devel-0.9.2-3.12.1
SUSE Linux Enterprise Workstation Extension 12 SP5
libpodofo0_9_2-0.9.2-3.12.1
Ссылки
- Link for SUSE-SU-2022:1690-1
- E-Mail link for SUSE-SU-2022:1690-1
- SUSE Security Ratings
- SUSE Bug 1159921
- SUSE CVE CVE-2019-20093 page
Описание
The PoDoFo::PdfVariant::DelayedLoad function in PdfVariant.h in PoDoFo 0.9.6 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file, because of ImageExtractor.cpp.
Затронутые продукты
SUSE Linux Enterprise Software Development Kit 12 SP5:libpodofo-devel-0.9.2-3.12.1
SUSE Linux Enterprise Workstation Extension 12 SP5:libpodofo0_9_2-0.9.2-3.12.1
Ссылки
- CVE-2019-20093
- SUSE Bug 1159921