Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 501
Alerts This Week
Warning Icon 1 501

Ubuntu 15.10 USN-2958-1 Critical: Poppler Denial Of Service

ubuntu
Calendar Grey May 2, 2016
Scroller Ubuntu
Recent vulnerabilities in Poppler may result in system crashes or unintended code execution on Ubuntu platforms. It's crucial to apply significant updates.
poppler could be made to crash or run programs if it opened a specially crafted file.

Summary

poppler could be made to crash or run programs if it opened a specially

crafted file.

Software Description:

- poppler: PDF rendering library

Details:

It was discovered that the poppler pdfseparate tool incorrectly handled

certain filenames. A local attacker could use this issue to cause the tool

to crash, resulting in a denial of service, or possibly execute arbitrary

code. This issue only applied to Ubuntu 12.04 LTS. (CVE-2013-4473,

CVE-2013-4474)

It was discovered that poppler incorrectly parsed certain malformed PDF

documents. If a user or automated system were tricked into opening a

crafted PDF file, an attacker could cause a denial of service or possibly

execute arbitrary code with privileges of the user invoking the program.

(CVE-2015-8868)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.10:
  libpoppler-cpp0                 0.33.0-0ubuntu3.1
  libpoppler-glib8                0.33.0-0ubuntu3.1
  libpoppler-qt4-4                0.33.0-0ubuntu3.1
  libpoppler-qt5-1                0.33.0-0ubuntu3.1
  libpoppler52                    0.33.0-0ubuntu3.1
  poppler-utils                   0.33.0-0ubuntu3.1

Ubuntu 14.04 LTS:
  libpoppler-cpp0                 0.24.5-2ubuntu4.4
  libpoppler-glib8                0.24.5-2ubuntu4.4
  libpoppler-qt4-4                0.24.5-2ubuntu4.4
  libpoppler-qt5-1                0.24.5-2ubuntu4.4
  libpoppler44                    0.24.5-2ubuntu4.4
  poppler-utils                   0.24.5-2ubuntu4.4

Ubuntu 12.04 LTS:
  libpoppler-cpp0                 0.18.4-1ubuntu3.2
  libpoppler-glib8                0.18.4-1ubuntu3.2
  libpoppler-qt4-3                0.18.4-1ubuntu3.2
  libpoppler19                    0.18.4-1ubuntu3.2
  poppler-utils                   0.18.4-1ubuntu3.2

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2958-1

CVE-2013-4473, CVE-2013-4474, CVE-2015-8868

Severity
critical
Lowest
Low
Medium
High
Critical

May 02, 2016

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.