Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
This update for poppler fixes the following issues: These security issues were fixed: - CVE-2017-14517: Prevent NULL Pointer dereference in the XRef::parseEntry() function via a crafted PDF document (bsc#1059066). - CVE-2017-9865: Fixed a stack-based buffer overflow vulnerability in GfxState.cc that would have allowed attackers to facilitate a denial-of-service attack via specially crafted PDF documents. (bsc#1045939) - CVE-2017-14518: Remedy a floating point exception in isImageInterpolationRequired() that could have been exploited using a specially crafted PDF document. (bsc#1059101) - CVE-2017-14520: Remedy a floating point exception in Splash::scaleImageYuXd() that could have been exploited using a specially crafted PDF document. (bsc#1059155)
#1045939 #1059066 #1059101 #1059155 #1060220
#1061092 #1061263 #1061264 #1061265 #1064593
#1074453
Cross- CVE-2017-1000456 CVE-2017-14517 CVE-2017-14518
CVE-2017-14520 CVE-2017-14617 CVE-2017-14928
CVE-2017-14975 CVE-2017-14976 CVE-2017-14977
CVE-2017-15565 CVE-2017-9865
Affected Products:
SUSE Linux Enterprise Software Development Kit 12-SP3
SUSE Linux Enterprise Server 12-SP3
SUSE Linux Enterprise Desktop 12-SP3
https://www.suse.com/security/cve/CVE-2017-1000456.html
https://www.suse.com/security/cve/CVE-2017-14517.html
https://www.suse.com/security/cve/CVE-2017-14518.html
https://www.suse.com/security/cve/CVE-2017-14520.html
https://www.suse.com/security/cve/CVE-2017-14617.html
https://www.suse.com/security/cve/CVE-2017-14928.html
Get the latest Linux and open source security news straight to your inbox.