Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Mageia: 2019-0245 Critical: Poppler Buffer Over-Read Advisory

mageia
Calendar Grey September 6, 2019
Dist Mageia Esm H88
Enhanced LibreOffice packages for Fedora resolve important memory corruption vulnerabilities and enhance security on Oct 12, 2020.
Updated poppler packages fix security vulnerabilities Poppler 0.74.0 has a heap-based buffer over-read in the CairoRescaleBox.cc downsample_row_box_filter function

Summary

Updated poppler packages fix security vulnerabilities
Poppler 0.74.0 has a heap-based buffer over-read in the CairoRescaleBox.cc downsample_row_box_filter function. (CVE-2019-9631)
PDFDoc::markObject in PDFDoc.cc in Poppler 0.74.0 mishandles dict marking, leading to stack consumption in the function Dict::find() located at Dict.cc, which can (for example) be triggered by passing a crafted pdf file to the pdfunite binary. (CVE-2019-9903)
An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function Splash::blitTransparent at splash/Splash.cc. (CVE-2019-10872)
An issue was discovered in Poppler 0.74.0. There is a NULL pointer dereference in the function SplashClip::clipAALine at splash/SplashClip.cc. (CVE-2019-10873)
In Poppler through 0.76.1, there is a heap-based buffer over-read in JPXStream::init in JPEG2000Stream.cc via data with inconsistent heights or widths. (CVE-2019-12293)
An issue was discovered in Poppler through 0.78.0. There is a divi...

Read the Full Advisory

References

- https://bugs.mageia.org/show_bug.cgi?id=25233

- https://access.redhat.com/errata/RHSA-2019:2022

- https://ubuntu.com/security/notices/USN-4042-1

- https://ubuntu.com/security/notices/USN-4091-1

- https://www.cve.org/CVERecord?id=CVE-2019-9631

- https://www.cve.org/CVERecord?id=CVE-2019-9903

- https://www.cve.org/CVERecord?id=CVE-2019-10872

- https://www.cve.org/CVERecord?id=CVE-2019-10873

- https://www.cve.org/CVERecord?id=CVE-2019-12293

- https://www.cve.org/CVERecord?id=CVE-2019-14494

Resolution

SRPMS

- 7/core/poppler-0.74.0-3.1.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 06 Sep 2019
URL: https://advisories.mageia.org/MGASA-2019-0245.html
Type: security
CVE: CVE-2019-9631, CVE-2019-9903, CVE-2019-10872, CVE-2019-10873, CVE-2019-12293, CVE-2019-14494

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here