Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

SUSE: 2024:3550-1 moderate: podofo application crash fixes

suse
Calendar Grey October 8, 2024
Dist Suse Esm H88
Essential patches for podofo fix various bugs, addressing app failures and avoiding service interruptions. Keep your system safe.
* bsc#1023072 * bsc#1023190 * bsc#1027776 * bsc#1027779 * bsc#1027785

Summary

## This update for podofo fixes the following issues: * CVE-2015-8981: Fixed heap overflow in the function ReadXRefSubsection (bsc#1023190) * CVE-2017-6840: Fixed invalid memory read in ColorChanger::GetColorFromStack (colorchanger.cpp) (bsc#1027787) * CVE-2017-6841: Fixed NULL pointer dereference in GraphicsStack::TGraphicsStackElement::~TGraphicsStackElement (graphicsstack.h) (bsc#1027786) * CVE-2017-6842: Fixed NULL pointer dereference in ColorChanger::GetColorFromStack (colorchanger.cpp) (bsc#1027785) * CVE-2017-6845: Fixed NULL pointer dereference in GraphicsStack::TGraphicsStackElement::SetNonStrokingColorSpace (graphicsstack.h) (bsc#1027779) * CVE-2017-6849: Fixed NULL pointer dereference in

References

* bsc#1023072

* bsc#1023190

* bsc#1027776

* bsc#1027779

* bsc#1027785

* bsc#1027786

* bsc#1027787

* bsc#1037000

* bsc#1075322

* bsc#1084894

Cross-

* CVE-2015-8981

* CVE-2017-6840

* CVE-2017-6841

* CVE-2017-6842

* CVE-2017-6845

* CVE-2017-6849

* CVE-2017-8378

* CVE-2018-5309

* CVE-2018-8001

CVSS scores:

* CVE-2017-6840 ( NVD ): 5.5 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

* CVE-2017-6841 ( NVD ): 5.5 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

* CVE-2017-6842 ( NVD ): 5.5 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

* CVE-2017-6845 ( NVD ): 5.5 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

* CVE-2017-6849 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

* CVE-2017-6849 ( NVD ): 5.5 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Announcement ID: SUSE-SU-2024:3550-1
Release Date: 2024-10-08T14:08:01Z
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here