Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2022:3385-1

Опубликовано: 26 сент. 2022
Источник: suse-cvrf

Описание

Security update for podofo

This update for podofo fixes the following issues:

  • CVE-2018-12983: Fixed a stack overrun (bsc#1099719).

Список пакетов

SUSE Linux Enterprise Software Development Kit 12 SP5
libpodofo-devel-0.9.2-3.15.1
SUSE Linux Enterprise Workstation Extension 12 SP5
libpodofo0_9_2-0.9.2-3.15.1

Описание

A stack-based buffer over-read in the PdfEncryptMD5Base::ComputeEncryptionKey() function in PdfEncrypt.cpp in PoDoFo 0.9.6-rc1 could be leveraged by remote attackers to cause a denial-of-service via a crafted pdf file.


Затронутые продукты
SUSE Linux Enterprise Software Development Kit 12 SP5:libpodofo-devel-0.9.2-3.15.1
SUSE Linux Enterprise Workstation Extension 12 SP5:libpodofo0_9_2-0.9.2-3.15.1

Ссылки