Alerts This Week
Warning Icon 1 758
Alerts This Week
Warning Icon 1 758

Ubuntu 18.04 LTS USN-6510-3 Moderate: DoS Vulnerability in ImageMagick

ubuntu
Calendar Grey November 29, 2023
Dist Ubuntu Esm H88
Ubuntu Security Notice USN-6521-7 addresses a minor flaw in libjpeg affecting Ubuntu 20.04 LTS. An update is recommended.
USN-6508-1 caused some minor regressions in poppler.

Summary

USN-6508-1 caused some minor regressions in poppler.

Software Description:

- poppler: PDF rendering library

Details:

USN-6508-1 fixed vulnerabilities in poppler. The update introduced

one minor regression in Ubuntu 18.04 LTS. This update fixes the

problem.

We apologize for the inconvenience.

Original advisory details:

It was discovered that poppler incorrectly handled certain malformed PDF

files. If a user or an automated system were tricked into opening a

specially crafted PDF file, a remote attacker could possibly use this

issue to cause a denial of service. This issue only affected Ubuntu 16.04

LTS, Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-23804)

It was discovered that poppler incorrectly handled certain malformed PDF

files. If a user or an automated system were tricked into opening a

specially crafted PDF file, a remote attacker could possibly use this

issue to cause a denial of service. (CVE-2022-37050, CVE-2022-37051,

CVE-20...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS (Available with Ubuntu Pro):
  libpoppler73                    0.62.0-2ubuntu2.14+esm3
  poppler-utils                   0.62.0-2ubuntu2.14+esm3

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-6508-2

https://ubuntu.com/security/notices/USN-6508-1

https://bugs.launchpad.net/ubuntu/+source/poppler/+bug/2045027

Severity
important
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-6508-2

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here