Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE 12-SP5: 2022:1724-1 Moderate: Poppler Memory Problems

suse
Calendar Grey May 18, 2022
Dist Suse Esm H88
Address security weaknesses present in Poppler for SUSE environments, applying essential updates and modifications to bolster system safety.
An update that fixes 7 vulnerabilities is now available

Summary

This update for poppler fixes the following issues: - CVE-2020-27778: Fixed a buffer overflow in pdftohtml (bsc#1179163). - CVE-2019-14494: Fixed a divide-by-zero error in pdftoppm (bsc#1143950). - CVE-2019-9959: Fixed an integer overflow in pdftocairo (bsc#1142465). - CVE-2019-10871: Fixed an invalid memory access in pdftops (bsc#1131696). - CVE-2019-10872: Fixed an invalid memory access in pdftoppm (bsc#1131722). - CVE-2019-9903: Fixed a buffer overflow in pdfunite (bsc#1130229). - CVE-2019-7310: Fixed an application crash in pdftocairo (bsc#1124150). - CVE-2019-9631: Fixed an invalid memory access in pdftocairo (bsc#1129202). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".

References

#1124150 #1129202 #1131696 #1131722 #1142465

#1143950 #1179163

Cross- CVE-2019-10871 CVE-2019-10872 CVE-2019-14494

CVE-2019-7310 CVE-2019-9631 CVE-2019-9959

CVE-2020-27778

CVSS scores:

CVE-2019-10871 (NVD) : 6.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

CVE-2019-10871 (SUSE): 4.4 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L

CVE-2019-10872 (NVD) : 8.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVE-2019-10872 (SUSE): 4.4 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L

CVE-2019-14494 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVE-2019-14494 (SUSE): 5.3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

CVE-2019-7310 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Announcement ID: SUSE-SU-2022:1724-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here