Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Debian 8: DLA-1939-1 Moderate: Poppler Denial Of Service Fix

debian lts
Calendar Grey September 30, 2019
Dist Debian Esm H88
Enhance poppler to resolve various security vulnerabilities, including denial of service and potential buffer overflow risks.
Several issues in poppler, a PDF rendering library, have been fixed

Summary

CVE-2018-20650

A missing check for the dict data type could lead to a denial of
service.

CVE-2018-21009

An integer overflow might happen in Parser::makeStream.

CVE-2019-12493

A stack-based buffer over-read by a crafted PDF file might happen in
PostScriptFunction::transform because some functions mishandle tint
transformation.


For Debian 8 "Jessie", these problems have been fixed in version
0.26.5-2+deb8u11.

We recommend that you upgrade your poppler packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS



Package: poppler
Version: 0.26.5-2+deb8u11
CVE ID: CVE-2018-20650 CVE-2018-21009 CVE-2019-12493

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here