Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

openSUSE: 2019:0066-1 Important: podofo Denial Of Service Fix

opensuse
Calendar Grey January 18, 2019
Dist Opensuse Esm H88
openSUSE Security Update: Security update for podofo _______________________________________________
An update that fixes 20 vulnerabilities is now available.

Description

This update for podofo version 0.9.6 fixes the following issues:

Security issues fixed:

- CVE-2017-5852: Fix a infinite loop in

PoDoFo::PdfPage::GetInheritedKeyFromObject (PdfPage.cpp) (boo#1023067)

- CVE-2017-5854: Fix a NULL pointer dereference in PdfOutputStream.cpp

(boo#1023070)

- CVE-2017-5886: Fix a heap-based buffer overflow in

PoDoFo::PdfTokenizer::GetNextToken (PdfTokenizer.cpp) (boo#1023380)

- CVE-2017-6844: Fix a buffer overflow in

PoDoFo::PdfParser::ReadXRefSubsection (PdfParser.cpp) (boo#1027782)

- CVE-2017-6847: Fix a NULL pointer dereference in

PoDoFo::PdfVariant::DelayedLoad (PdfVariant.h) (boo#1027778)

- CVE-2017-7379: Fix a heap-based buffer overflow in

PoDoFo::PdfSimpleEncoding::ConvertToEncoding (PdfEncoding.cpp)

(boo#1032018)

- CVE-2018-5296: Fix a denial of service in the ReadXRefSubsection

function (boo#1075021)

- CVE-2018-5309: Fix a integer overflow in the ReadObjectsFromStream

...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 42.3:

zypper in -t patch openSUSE-2019-66=1

Package List

- openSUSE Leap 42.3 (i586 x86_64):

libpodofo-devel-0.9.6-10.3.1

libpodofo0_9_6-0.9.6-10.3.1

libpodofo0_9_6-debuginfo-0.9.6-10.3.1

podofo-0.9.6-10.3.1

podofo-debuginfo-0.9.6-10.3.1

podofo-debugsource-0.9.6-10.3.1

References

https://www.suse.com/security/cve/CVE-2017-5852.html

https://www.suse.com/security/cve/CVE-2017-5853.html

https://www.suse.com/security/cve/CVE-2017-5854.html

https://www.suse.com/security/cve/CVE-2017-5855.html

https://www.suse.com/security/cve/CVE-2017-5886.html

https://www.suse.com/security/cve/CVE-2017-6840.html

https://www.suse.com/security/cve/CVE-2017-6844.html

https://www.suse.com/security/cve/CVE-2017-6845.html

https://www.suse.com/security/cve/CVE-2017-6847.html

https://www.suse.com/security/cve/CVE-2017-7378.html

https://www.suse.com/security/cve/CVE-2017-7379.html

https://www.suse.com/security/cve/CVE-2017-7380.html

https://www.suse.com/security/cve/CVE-2017-7994.html

https://www.suse.com/security/cve/CVE-2017-8054.html

https://www.suse.com/security/cve/CVE-2017-8787.html

https://www.suse.com/security/cve/CVE-2018-5295.html

https://www.suse.com/security/cve/CVE-2018-5296.html

https://www.suse.com/security/cve/CVE-2018-5308.html

https://www.suse.com/security/cve/CVE-2018-5309.html

https://www....

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2019:0066-1
Rating: important
Affected Products: openSUSE Leap 42.3

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here