Alerts This Week
Warning Icon 1 697
Alerts This Week
Warning Icon 1 697

Mageia 2020-0234 High Severity: Security Issue in Libarchive Detected

mageia
Calendar Grey March 29, 2019
Dist Mageia Esm H88
Enhanced poppler distributions in Mageia rectify vulnerabilities leading to service interruptions during PDF processing.
The updated poppler packages fix security vulnerabilities: In Poppler 0.72.0, PDFDoc::setup in PDFDoc.cc allows attackers to cause a denial-of-service (application crash caused by...

Summary

The updated poppler packages fix security vulnerabilities:
In Poppler 0.72.0, PDFDoc::setup in PDFDoc.cc allows attackers to cause a denial-of-service (application crash caused by Object.h SIGABRT, because of a wrong return value from PDFDoc::setup) by crafting a PDF file in which an xref data structure is mishandled during extractPDFSubtype processing. (CVE-2018-20662)
A heap-based buffer underwrite exists in ImageStream::getLine() located at Stream.cc in Poppler 0.74.0 that can (for example) be triggered by sending a crafted PDF file to the pdfimages binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. (CVE-2019-9200)

References

- https://bugs.mageia.org/show_bug.cgi?id=24495

- https://ubuntu.com/security/notices/USN-3905-1

- https://www.cve.org/CVERecord?id=CVE-2018-20662

- https://www.cve.org/CVERecord?id=CVE-2019-9200

Resolution

SRPMS

- 6/core/poppler-0.52.0-3.12.mga6

Publication date: 29 Mar 2019
URL: https://advisories.mageia.org/MGASA-2019-0117.html
Type: security
CVE: CVE-2018-20662, CVE-2019-9200

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here