Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2023:4562-1

Опубликовано: 24 нояб. 2023
Источник: suse-cvrf

Описание

Security update for poppler

This update for poppler fixes the following issues:

  • CVE-2019-9545: Fixed an uncontrolled recursion issue that could cause a crash (bsc#1128114).
  • CVE-2022-37052: Fixed a crash that could be triggered when opening a crafted file (bsc#1214726).
  • CVE-2020-36023: Fixed a stack bugger overflow in FoFiType1C:cvtGlyph (bsc#1214256).

Список пакетов

SUSE Linux Enterprise Module for Basesystem 15 SP4
libpoppler89-0.79.0-150200.3.26.1
SUSE Linux Enterprise Module for Basesystem 15 SP5
libpoppler89-0.79.0-150200.3.26.1
SUSE Manager Proxy 4.2
libpoppler-cpp0-0.79.0-150200.3.26.1
libpoppler-devel-0.79.0-150200.3.26.1
libpoppler-glib-devel-0.79.0-150200.3.26.1
libpoppler-glib8-0.79.0-150200.3.26.1
libpoppler89-0.79.0-150200.3.26.1
poppler-tools-0.79.0-150200.3.26.1
typelib-1_0-Poppler-0_18-0.79.0-150200.3.26.1
SUSE Manager Server 4.2
libpoppler-cpp0-0.79.0-150200.3.26.1
libpoppler-devel-0.79.0-150200.3.26.1
libpoppler-glib-devel-0.79.0-150200.3.26.1
libpoppler-glib8-0.79.0-150200.3.26.1
libpoppler89-0.79.0-150200.3.26.1
poppler-tools-0.79.0-150200.3.26.1
typelib-1_0-Poppler-0_18-0.79.0-150200.3.26.1
openSUSE Leap 15.4
libpoppler89-0.79.0-150200.3.26.1
libpoppler89-32bit-0.79.0-150200.3.26.1

Описание

An issue was discovered in Poppler 0.74.0. A recursive function call, in JBIG2Stream::readTextRegion() located in JBIG2Stream.cc, can be triggered by sending a crafted pdf file to (for example) the pdfimages binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. This is related to JBIG2Bitmap::clearToZero.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP4:libpoppler89-0.79.0-150200.3.26.1
SUSE Linux Enterprise Module for Basesystem 15 SP5:libpoppler89-0.79.0-150200.3.26.1
SUSE Manager Proxy 4.2:libpoppler-cpp0-0.79.0-150200.3.26.1
SUSE Manager Proxy 4.2:libpoppler-devel-0.79.0-150200.3.26.1

Ссылки

Описание

An issue was discovered in freedesktop poppler version 20.12.1, allows remote attackers to cause a denial of service (DoS) via crafted .pdf file to FoFiType1C::cvtGlyph function.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP4:libpoppler89-0.79.0-150200.3.26.1
SUSE Linux Enterprise Module for Basesystem 15 SP5:libpoppler89-0.79.0-150200.3.26.1
SUSE Manager Proxy 4.2:libpoppler-cpp0-0.79.0-150200.3.26.1
SUSE Manager Proxy 4.2:libpoppler-devel-0.79.0-150200.3.26.1

Ссылки

Описание

A reachable Object::getString assertion in Poppler 22.07.0 allows attackers to cause a denial of service due to a failure in markObject.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP4:libpoppler89-0.79.0-150200.3.26.1
SUSE Linux Enterprise Module for Basesystem 15 SP5:libpoppler89-0.79.0-150200.3.26.1
SUSE Manager Proxy 4.2:libpoppler-cpp0-0.79.0-150200.3.26.1
SUSE Manager Proxy 4.2:libpoppler-devel-0.79.0-150200.3.26.1

Ссылки