Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2022:1690-1

Опубликовано: 16 мая 2022
Источник: suse-cvrf

Описание

Security update for podofo

This update for podofo fixes the following issues:

  • CVE-2019-20093: Fixed an invalid memory access that could cause an application crash (bsc#1159921).

Список пакетов

SUSE Linux Enterprise Software Development Kit 12 SP5
libpodofo-devel-0.9.2-3.12.1
SUSE Linux Enterprise Workstation Extension 12 SP5
libpodofo0_9_2-0.9.2-3.12.1

Описание

The PoDoFo::PdfVariant::DelayedLoad function in PdfVariant.h in PoDoFo 0.9.6 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file, because of ImageExtractor.cpp.


Затронутые продукты
SUSE Linux Enterprise Software Development Kit 12 SP5:libpodofo-devel-0.9.2-3.12.1
SUSE Linux Enterprise Workstation Extension 12 SP5:libpodofo0_9_2-0.9.2-3.12.1

Ссылки