Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Ubuntu 20.04: 2020-d8efc775e3 High: Ghostscript Heap Overflow

fedora
Calendar Grey April 27, 2018
Dist Fedora Esm H88
Important security update for qpdf to mitigate stack overflow issues in Fedora 28. Ensure you have the latest version for safe PDF handling.
Security fix for CVE-2018-9918

Summary

QPDF is a command-line program that does structural, content-preserving

transformations on PDF files. It could have been called something

like pdf-to-pdf. It includes support for merging and splitting PDFs

and to manipulate the list of pages in a PDF file. It is not a PDF viewer

or a program capable of converting PDF into other formats.

Security fix for CVE-2018-9918

* Mon Apr 16 2018 Zdenek Dohnal - 7.1.1-5

- CVE-2018-9918 qpdf: stack exhaustion in QPDFObjectHandle and QPDF_Dictionary classes in libqpdf.a [fedora-all]

[ 1 ] Bug #1566756 - CVE-2018-9918 qpdf: stack exhaustion in QPDFObjectHandle and QPDF_Dictionary classes in libqpdf.a

https://bugzilla.redhat.com/show_bug.cgi?id=1566756

su -c 'dnf upgrade --advisory FEDORA-2018-b4ef545db5' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Change Log

References

Update Instructions

Product: Fedora 28
Version: 7.1.1
Release: 5.fc28
Summary: Command-line tools and library for transforming PDF files

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here