Package        : poppler
Version        : 0.26.5-2+deb8u11
CVE ID         : CVE-2018-20650 CVE-2018-21009 CVE-2019-12493


Several issues in poppler, a PDF rendering library, have been fixed.

CVE-2018-20650

     A missing check for the dict data type could lead to a denial of
     service.

CVE-2018-21009

     An integer overflow might happen in Parser::makeStream.

CVE-2019-12493

     A stack-based buffer over-read by a crafted PDF file might happen in
     PostScriptFunction::transform because some functions  mishandle tint
     transformation.


For Debian 8 "Jessie", these problems have been fixed in version
0.26.5-2+deb8u11.

We recommend that you upgrade your poppler packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

Debian LTS: DLA-1939-1: poppler security update

September 30, 2019
Several issues in poppler, a PDF rendering library, have been fixed

Summary

CVE-2018-20650

A missing check for the dict data type could lead to a denial of
service.

CVE-2018-21009

An integer overflow might happen in Parser::makeStream.

CVE-2019-12493

A stack-based buffer over-read by a crafted PDF file might happen in
PostScriptFunction::transform because some functions mishandle tint
transformation.


For Debian 8 "Jessie", these problems have been fixed in version
0.26.5-2+deb8u11.

We recommend that you upgrade your poppler packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS



Severity
Package : poppler
Version : 0.26.5-2+deb8u11
CVE ID : CVE-2018-20650 CVE-2018-21009 CVE-2019-12493

Related News