Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2022:1723-1

Опубликовано: 18 мая 2022
Источник: suse-cvrf

Описание

Security update for poppler

This update for poppler fixes the following issues:

  • CVE-2020-27778: Fixed a buffer overflow in pdftohtml (bsc#1179163).
  • CVE-2019-14494: Fixed a divide-by-zero error in pdftoppm (bsc#1143950).
  • CVE-2019-9959: Fixed an integer overflow in pdftocairo (bsc#1142465).
  • CVE-2019-10871: Fixed an invalid memory access in pdftops (bsc#1131696).
  • CVE-2019-10872: Fixed an invalid memory access in pdftoppm (bsc#1131722).
  • CVE-2019-9903: Fixed a buffer overflow in pdfunite (bsc#1130229).
  • CVE-2019-7310: Fixed an application crash in pdftocairo (bsc#1124150).
  • CVE-2019-9631: Fixed an invalid memory access in pdftocairo (bsc#1129202).

Список пакетов

SUSE Linux Enterprise Server 12 SP5
libpoppler-glib8-0.43.0-16.19.3
libpoppler-qt4-4-0.43.0-16.19.3
libpoppler60-0.43.0-16.19.3
poppler-tools-0.43.0-16.19.3
SUSE Linux Enterprise Server for SAP Applications 12 SP5
libpoppler-glib8-0.43.0-16.19.3
libpoppler-qt4-4-0.43.0-16.19.3
libpoppler60-0.43.0-16.19.3
poppler-tools-0.43.0-16.19.3
SUSE Linux Enterprise Software Development Kit 12 SP5
libpoppler-cpp0-0.43.0-16.19.3
libpoppler-devel-0.43.0-16.19.3
libpoppler-glib-devel-0.43.0-16.19.3
libpoppler-qt4-devel-0.43.0-16.19.3
typelib-1_0-Poppler-0_18-0.43.0-16.19.3

Описание

An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function PSOutputDev::checkPageSlice at PSOutputDev.cc.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP5:libpoppler-glib8-0.43.0-16.19.3
SUSE Linux Enterprise Server 12 SP5:libpoppler-qt4-4-0.43.0-16.19.3
SUSE Linux Enterprise Server 12 SP5:libpoppler60-0.43.0-16.19.3
SUSE Linux Enterprise Server 12 SP5:poppler-tools-0.43.0-16.19.3

Ссылки

Описание

An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function Splash::blitTransparent at splash/Splash.cc.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP5:libpoppler-glib8-0.43.0-16.19.3
SUSE Linux Enterprise Server 12 SP5:libpoppler-qt4-4-0.43.0-16.19.3
SUSE Linux Enterprise Server 12 SP5:libpoppler60-0.43.0-16.19.3
SUSE Linux Enterprise Server 12 SP5:poppler-tools-0.43.0-16.19.3

Ссылки

Описание

An issue was discovered in Poppler through 0.78.0. There is a divide-by-zero error in the function SplashOutputDev::tilingPatternFill at SplashOutputDev.cc.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP5:libpoppler-glib8-0.43.0-16.19.3
SUSE Linux Enterprise Server 12 SP5:libpoppler-qt4-4-0.43.0-16.19.3
SUSE Linux Enterprise Server 12 SP5:libpoppler60-0.43.0-16.19.3
SUSE Linux Enterprise Server 12 SP5:poppler-tools-0.43.0-16.19.3

Ссылки

Описание

In Poppler 0.73.0, a heap-based buffer over-read (due to an integer signedness error in the XRef::getEntry function in XRef.cc) allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PDF document, as demonstrated by pdftocairo.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP5:libpoppler-glib8-0.43.0-16.19.3
SUSE Linux Enterprise Server 12 SP5:libpoppler-qt4-4-0.43.0-16.19.3
SUSE Linux Enterprise Server 12 SP5:libpoppler60-0.43.0-16.19.3
SUSE Linux Enterprise Server 12 SP5:poppler-tools-0.43.0-16.19.3

Ссылки

Описание

Poppler 0.74.0 has a heap-based buffer over-read in the CairoRescaleBox.cc downsample_row_box_filter function.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP5:libpoppler-glib8-0.43.0-16.19.3
SUSE Linux Enterprise Server 12 SP5:libpoppler-qt4-4-0.43.0-16.19.3
SUSE Linux Enterprise Server 12 SP5:libpoppler60-0.43.0-16.19.3
SUSE Linux Enterprise Server 12 SP5:poppler-tools-0.43.0-16.19.3

Ссылки

Описание

PDFDoc::markObject in PDFDoc.cc in Poppler 0.74.0 mishandles dict marking, leading to stack consumption in the function Dict::find() located at Dict.cc, which can (for example) be triggered by passing a crafted pdf file to the pdfunite binary.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP5:libpoppler-glib8-0.43.0-16.19.3
SUSE Linux Enterprise Server 12 SP5:libpoppler-qt4-4-0.43.0-16.19.3
SUSE Linux Enterprise Server 12 SP5:libpoppler60-0.43.0-16.19.3
SUSE Linux Enterprise Server 12 SP5:poppler-tools-0.43.0-16.19.3

Ссылки

Описание

The JPXStream::init function in Poppler 0.78.0 and earlier doesn't check for negative values of stream length, leading to an Integer Overflow, thereby making it possible to allocate a large memory chunk on the heap, with a size controlled by an attacker, as demonstrated by pdftocairo.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP5:libpoppler-glib8-0.43.0-16.19.3
SUSE Linux Enterprise Server 12 SP5:libpoppler-qt4-4-0.43.0-16.19.3
SUSE Linux Enterprise Server 12 SP5:libpoppler60-0.43.0-16.19.3
SUSE Linux Enterprise Server 12 SP5:poppler-tools-0.43.0-16.19.3

Ссылки

Описание

A flaw was found in Poppler in the way certain PDF files were converted into HTML. A remote attacker could exploit this flaw by providing a malicious PDF file that, when processed by the 'pdftohtml' program, would crash the application causing a denial of service.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP5:libpoppler-glib8-0.43.0-16.19.3
SUSE Linux Enterprise Server 12 SP5:libpoppler-qt4-4-0.43.0-16.19.3
SUSE Linux Enterprise Server 12 SP5:libpoppler60-0.43.0-16.19.3
SUSE Linux Enterprise Server 12 SP5:poppler-tools-0.43.0-16.19.3

Ссылки
Уязвимость SUSE-SU-2022:1723-1