Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

SUSE: 2018:1662-1 Moderate: Poppler 11 Vulnerability Fix

suse
Calendar Grey June 12, 2018
Scroller Suse
SUSE Security Bulletin: Resolves 11 threats in poppler, classified as moderate. Essential installation instructions included.
An update that fixes 11 vulnerabilities is now available

Summary

This update for poppler fixes the following issues: These security issues were fixed: - CVE-2017-14517: Prevent NULL Pointer dereference in the XRef::parseEntry() function via a crafted PDF document (bsc#1059066). - CVE-2017-9865: Fixed a stack-based buffer overflow vulnerability in GfxState.cc that would have allowed attackers to facilitate a denial-of-service attack via specially crafted PDF documents. (bsc#1045939) - CVE-2017-14518: Remedy a floating point exception in isImageInterpolationRequired() that could have been exploited using a specially crafted PDF document. (bsc#1059101) - CVE-2017-14520: Remedy a floating point exception in Splash::scaleImageYuXd() that could have been exploited using a specially crafted PDF document. (bsc#1059155)

References

#1045939 #1059066 #1059101 #1059155 #1060220

#1061092 #1061263 #1061264 #1061265 #1064593

#1074453

Cross- CVE-2017-1000456 CVE-2017-14517 CVE-2017-14518

CVE-2017-14520 CVE-2017-14617 CVE-2017-14928

CVE-2017-14975 CVE-2017-14976 CVE-2017-14977

CVE-2017-15565 CVE-2017-9865

Affected Products:

SUSE Linux Enterprise Software Development Kit 12-SP3

SUSE Linux Enterprise Server 12-SP3

SUSE Linux Enterprise Desktop 12-SP3

https://www.suse.com/security/cve/CVE-2017-1000456.html

https://www.suse.com/security/cve/CVE-2017-14517.html

https://www.suse.com/security/cve/CVE-2017-14518.html

https://www.suse.com/security/cve/CVE-2017-14520.html

https://www.suse.com/security/cve/CVE-2017-14617.html

https://www.suse.com/security/cve/CVE-2017-14928.html

Announcement ID: SUSE-SU-2018:1662-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.