Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE: 2020:1626-1 Moderate: Poppler Denial of Service Issues

suse
Calendar Grey June 16, 2020
Dist Suse Esm H88
SUSE Security Patch addresses numerous vulnerabilities in ImageMagick, notably problems related to denial of service and invalid memory access.
An update that fixes 5 vulnerabilities is now available

Summary

This update for poppler fixes the following issues: These security issues were fixed: - CVE-2017-14617: Fixed a floating point exception in Stream.cc, which may lead to a potential attack when handling malicious PDF files. (bsc#1060220) - CVE-2017-1000456: Validate boundaries in TextPool::addWord to prevent overflows in subsequent calculations (bsc#1074453) - CVE-2017-15565: Prevent NULL Pointer dereference in the GfxImageColorMap::getGrayLine() function via a crafted PDF document (bsc#1064593) - CVE-2018-10768: Prevent NULL pointer dereference in the AnnotPath::getCoordsLength function. A crafted input could have lead to a remote denial of service attack (bsc#1092105). This update also fixes an additional segmentation fault that is trigger by the reproducer for CVE-2017-14517 (bsc#1059066).

References

#1059066 #1060220 #1064593 #1074453 #1092105

Cross- CVE-2017-1000456 CVE-2017-14517 CVE-2017-14617

CVE-2017-15565 CVE-2018-10768

Affected Products:

SUSE Linux Enterprise Software Development Kit 12-SP5

SUSE Linux Enterprise Software Development Kit 12-SP4

https://www.suse.com/security/cve/CVE-2017-1000456.html

https://www.suse.com/security/cve/CVE-2017-14517.html

https://www.suse.com/security/cve/CVE-2017-14617.html

https://www.suse.com/security/cve/CVE-2017-15565.html

https://www.suse.com/security/cve/CVE-2018-10768.html

https://bugzilla.suse.com/1059066

https://bugzilla.suse.com/1060220

https://bugzilla.suse.com/1064593

https://bugzilla.suse.com/1074453

https://bugzilla.suse.com/1092105

Announcement ID: SUSE-SU-2020:1626-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here