Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
197

Debian 10 Buster DLA-3620-1 Critical Update for Poppler Overflow Issues

Several vulnerabilities have been fixed in poppler, a PDF rendering library. CVE-2020-23804 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3620-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Adrian Bunk October 16, 2023 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : poppler Version : 0.71.0-5+deb10u3 CVE ID : CVE-2020-23804 CVE-2022-37050 CVE-2022-37051 Several vulnerabilities have been fixed in poppler, a PDF rendering library. CVE-2020-23804 Stack overflow in XRef::readXRefTable() CVE-2022-37050 Crash in PDFDoc::savePageAs() CVE-2022-37051 Crash in the pdfunite tool For Debian 10 buster, these problems have been fixed in version 0.71.0-5+deb10u3. We recommend that you upgrade your poppler packages. For the detailed security status of poppler please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/poppler Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS has released vital security patches addressing several vulnerabilities in poppler, the PDF rendering library, ensuring system integrity and protection against threats. Debian LTS, Poppler Update, Security Issues, PDF Library Fix. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Oct 16, 2023 Critical Debian LTS
172

Ubuntu 18.04 & 16.04: USN-4646-1 Critical Poppler DoS Advisory

Several security issues were fixed in poppler.. =========================================================================Ubuntu Security Notice USN-4646-1 November 25, 2020 poppler vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS Summary: Several security issues were fixed in poppler. Software Description: - poppler: PDF rendering library Details: It was discovered that Poppler incorrectly handled certain files. If a user or automated system were tricked into opening a crafted PDF file, an attacker could cause a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: libpoppler73 0.62.0-2ubuntu2.11 poppler-utils 0.62.0-2ubuntu2.11 Ubuntu 16.04 LTS: libpoppler58 0.41.0-0ubuntu1.15 poppler-utils 0.41.0-0ubuntu1.15 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-4646-1 CVE-2018-21009, CVE-2019-10871, CVE-2019-13283, CVE-2019-9959, CVE-2020-27778 Package Information: https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.11 https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.15 . Several vulnerabilities addressed in Ghostscript released in Ubuntu via USN-4650-1, affecting releases 20.04 and 22.04.. Poppler Security Update, Ubuntu Denial Of Service, PDF Rendering Issues. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Nov 25, 2020 Critical Ubuntu
197

Debian 8: DLA-1752-1 Critical: Poppler Buffer Over-read Issue

A security issue was discovered in the poppler PDF rendering shared library. . Package : poppler Version : 0.26.5-2+deb8u9 CVE ID : CVE-2019-9631 Debian Bug : A security issue was discovered in the poppler PDF rendering shared library. The Poppler shared library had a heap-based buffer over-read in the CairoRescaleBox.cc downsample_row_box_filter function. For Debian 8 "Jessie", this problem has been fixed in version 0.26.5-2+deb8u9. We recommend that you upgrade your poppler packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -- mike gabriel aka sunweaver (Debian Developer) fon: +49 (1520) 1976 148 GnuPG Fingerprint: 9BFB AEE8 6C0A A5FF BF22 0782 9AF4 6B30 2577 1B31 mail: This email address is being protected from spambots. You need JavaScript enabled to view it., https://sunweavers.net/ . An alarming vulnerability was found in the libjpeg image processing library, necessitating an immediate patch to maintain data integrity.. Debian Security Update, Poppler Library, Buffer Over-read, PDF Issue. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 08, 2019 Critical Debian LTS
89

Fedora: Security Advisory for Poppler Critical Fixes and Updates

Security fix for CVE-2018-20662, CVE-2019-9631 and CVE-2019-9200. One additional fix for crash detected by ABRT.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2019-13ba3be562 2019-04-05 01:54:23.968729 --------------------------------------------------------------------------------Name : poppler Product : Fedora 28 Version : 0.62.0 Release : 20.fc28 URL : http://poppler.freedesktop.org/ Summary : PDF rendering library Description : poppler is a PDF rendering library. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2018-20662, CVE-2019-9631 and CVE-2019-9200. One additional fix for crash detected by ABRT. --------------------------------------------------------------------------------ChangeLog: * Mon Apr 1 2019 Marek Kasik - 0.62.0-20 - Constrain number of cycles in rescale filter - Compute correct coverage values for box filter - Resolves: #1686803 * Mon Apr 1 2019 Marek Kasik - 0.62.0-19 - Check for Ref type before unwrapping Object - Resolves: #1694457 * Mon Mar 11 2019 Marek Kasik - 0.62.0-18 - Fix possible crash on broken files in ImageStream::getLine() - Resolves: #1683633 * Fri Mar 8 2019 Marek Kasik - 0.62.0-17 - Synchronize previous patch with upstream (and enable it...) - Related: #1665274 * Wed Feb 20 2019 Marek Kasik - 0.62.0-16 - Check Catalog from XRef for being a Dict - Resolves: #1665274 * Wed Feb 20 2019 Marek Kasik - 0.62.0-15 - Defend against requests for negative XRef indices - Resolves: #1672420 * Tue Jan 22 2019 Marek Kasik - 0.62.0-14 - Avoid global display profile state becoming an uncontrolled - memory leak - Resolves: #1646549 * Mon Jan 21 2019 Marek Kasik - 0.62.0-13 - Do not try to parse into unallocated XRef entry - Resolves: #1665268 * Mon Jan 21 2019 Marek Kasik - 0.62.0-12 - Move the fileSpec.dictLookup call inside fileSpec.isDict if -Resolves: #1665264 * Mon Jan 21 2019 Marek Kasik - 0.62.0-11 - Do not try to construct invalid rich media annotation assets - Resolves: #1665260 * Thu Nov 15 2018 Marek Kasik - 0.62.0-10 - Check for valid file name of embedded file - Resolves: #1649451 * Thu Nov 15 2018 Marek Kasik - 0.62.0-9 - Check for valid embedded file before trying to save it - Resolves: #1649441 * Thu Nov 15 2018 Marek Kasik - 0.62.0-8 - Check for stream before calling stream methods - when saving an embedded file - Resolves: #1649436 * Mon Nov 12 2018 Marek Kasik - 0.62.0-7 - Avoid cycles in PDF parsing - Resolves: #1626620 * Wed Oct 17 2018 Marek Kasik - 0.62.0-6 - Use python3 in make-glib-api-docs and gtkdoc.py * Wed Oct 17 2018 Marek Kasik - 0.62.0-5 - Fix crash on missing embedded file - Resolves: #1569334 * Tue Aug 7 2018 Marek Kasik - 0.62.0-4 - Fix tiling patterns when pattern cell is too far - Resolves: #1557355 * Thu Jul 26 2018 Marek Kasik - 0.62.0-3 - Fix crash when Object has negative number (CVE-2018-13988) - Resolves: #1607461 * Mon May 28 2018 Marek Kasik - 0.62.0-2 - Fix infinite recursion (CVE-2017-18267) - Resolves: #1578780 --------------------------------------------------------------------------------References: [ 1 ] Bug #1665273 - CVE-2018-20662 poppler: SIGABRT PDFDoc::setup class in PDFDoc.cc https://bugzilla.redhat.com/show_bug.cgi?id=1665273 [ 2 ] Bug #1683632 - CVE-2019-9200 poppler: heap-based buffer overflow in function ImageStream::getLine() in Stream.cc https://bugzilla.redhat.com/show_bug.cgi?id=1683632 [ 3 ] Bug #1686802 - CVE-2019-9631 poppler: heap-based buffer over-read in function downsample_row_box_filter in CairoRescaleBox.cc https://bugzilla.redhat.com/show_bug.cgi?id=1686802 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2019-13ba3be562' at the command line. For moreinformation, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . Patch release for libpng addressing severe flaws and system instability including memory corruption issues. Discover additional details!. Poppler Security Update,Fedora PDF Rendering,User Spaces Security Fix,PDF Library Issues. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Apr 04, 2019 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":548,"type":"x","order":1,"pct":78.51,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.3,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.87,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.32,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here