Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2023:3947-1

Опубликовано: 03 окт. 2023
Источник: suse-cvrf

Описание

Security update for poppler

This update for poppler fixes the following issues:

  • CVE-2022-37050: Fixed denial-of-service via savePageAs in PDFDoc.c (bsc#1214622).
  • CVE-2022-37051: Fixed abort in main() in pdfunite.cc (bsc#1214621).
  • CVE-2022-38349: Fixed reachable assertion in Object.h that will lead to denial of service (bsc#1214618).

Список пакетов

SUSE Linux Enterprise Module for Basesystem 15 SP4
libpoppler-cpp0-22.01.0-150400.3.11.2
libpoppler-devel-22.01.0-150400.3.11.2
libpoppler-glib-devel-22.01.0-150400.3.11.2
libpoppler-glib8-22.01.0-150400.3.11.2
libpoppler117-22.01.0-150400.3.11.2
poppler-tools-22.01.0-150400.3.11.2
typelib-1_0-Poppler-0_18-22.01.0-150400.3.11.2
SUSE Linux Enterprise Module for Package Hub 15 SP4
libpoppler-cpp0-22.01.0-150400.3.11.2
libpoppler-devel-22.01.0-150400.3.11.2
libpoppler-glib8-32bit-22.01.0-150400.3.11.2
libpoppler-qt5-1-22.01.0-150400.3.11.2
libpoppler-qt5-devel-22.01.0-150400.3.11.2
libpoppler117-32bit-22.01.0-150400.3.11.2
SUSE Linux Enterprise Workstation Extension 15 SP5
libpoppler117-22.01.0-150400.3.11.2
openSUSE Leap 15.4
libpoppler-cpp0-22.01.0-150400.3.11.2
libpoppler-cpp0-32bit-22.01.0-150400.3.11.2
libpoppler-devel-22.01.0-150400.3.11.2
libpoppler-glib-devel-22.01.0-150400.3.11.2
libpoppler-glib8-22.01.0-150400.3.11.2
libpoppler-glib8-32bit-22.01.0-150400.3.11.2
libpoppler-qt5-1-22.01.0-150400.3.11.2
libpoppler-qt5-1-32bit-22.01.0-150400.3.11.2
libpoppler-qt5-devel-22.01.0-150400.3.11.2
libpoppler-qt6-3-22.01.0-150400.3.11.2
libpoppler-qt6-devel-22.01.0-150400.3.11.2
libpoppler117-22.01.0-150400.3.11.2
libpoppler117-32bit-22.01.0-150400.3.11.2
poppler-tools-22.01.0-150400.3.11.2
typelib-1_0-Poppler-0_18-22.01.0-150400.3.11.2

Описание

In Poppler 22.07.0, PDFDoc::savePageAs in PDFDoc.c callows attackers to cause a denial-of-service (application crashes with SIGABRT) by crafting a PDF file in which the xref data structure is mishandled in getCatalog processing. Note that this vulnerability is caused by the incomplete patch of CVE-2018-20662.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP4:libpoppler-cpp0-22.01.0-150400.3.11.2
SUSE Linux Enterprise Module for Basesystem 15 SP4:libpoppler-devel-22.01.0-150400.3.11.2
SUSE Linux Enterprise Module for Basesystem 15 SP4:libpoppler-glib-devel-22.01.0-150400.3.11.2
SUSE Linux Enterprise Module for Basesystem 15 SP4:libpoppler-glib8-22.01.0-150400.3.11.2

Ссылки

Описание

An issue was discovered in Poppler 22.07.0. There is a reachable abort which leads to denial of service because the main function in pdfunite.cc lacks a stream check before saving an embedded file.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP4:libpoppler-cpp0-22.01.0-150400.3.11.2
SUSE Linux Enterprise Module for Basesystem 15 SP4:libpoppler-devel-22.01.0-150400.3.11.2
SUSE Linux Enterprise Module for Basesystem 15 SP4:libpoppler-glib-devel-22.01.0-150400.3.11.2
SUSE Linux Enterprise Module for Basesystem 15 SP4:libpoppler-glib8-22.01.0-150400.3.11.2

Ссылки

Описание

An issue was discovered in Poppler 22.08.0. There is a reachable assertion in Object.h, will lead to denial of service because PDFDoc::replacePageDict in PDFDoc.cc lacks a stream check before saving an embedded file.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP4:libpoppler-cpp0-22.01.0-150400.3.11.2
SUSE Linux Enterprise Module for Basesystem 15 SP4:libpoppler-devel-22.01.0-150400.3.11.2
SUSE Linux Enterprise Module for Basesystem 15 SP4:libpoppler-glib-devel-22.01.0-150400.3.11.2
SUSE Linux Enterprise Module for Basesystem 15 SP4:libpoppler-glib8-22.01.0-150400.3.11.2

Ссылки