Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 507
Alerts This Week
Warning Icon 1 507

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 1 articles for you...
172

Ubuntu 24.04 LTS USN-6915-1 Moderate: Poppler Denial of Service

poppler could be made to denial of service if it opened a specially crafted PDF.. ========================================================================== Ubuntu Security Notice USN-6915-1 July 24, 2024 poppler vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: poppler could be made to denial of service if it opened a specially crafted PDF. Software Description: - poppler: PDF rendering library Details: It was discovered that poppler incorrectly handled certain malformed PDF. An attacker could possibly use this issue to cause a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS libpoppler134 24.02.0-1ubuntu9.1 poppler-utils 24.02.0-1ubuntu9.1 Ubuntu 22.04 LTS libpoppler118 22.02.0-2ubuntu0.5 poppler-utils 22.02.0-2ubuntu0.5 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6915-1 CVE-2024-6239 Package Information: https://launchpad.net/ubuntu/+source/poppler/24.02.0-1ubuntu9.1 https://launchpad.net/ubuntu/+source/poppler/22.02.0-2ubuntu0.5 . The Ubuntu Security Notice USN-6915-1 concerns a critical vulnerability in poppler that could lead to denial of service attacks arising from incorrectly formatted PDFs.. Ubuntu Security Notice, Poppler PDF, Denial of Service, Security Updates. . LinuxSecurity.com Team

Calendar%202 Jul 24, 2024 Ubuntu
197

Debian 10: DLA-3120-1 Critical: Poppler DoS Threat Details

Several security vulnerabilities have been discovered in Poppler, a PDF rendering library, that could lead to denial of service or possibly other unspecified impact when processing maliciously crafted documents. . -------------------------------------------------------------------------Debian LTS Advisory DLA-3120-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Markus Koschany September 26, 2022 https://wiki.debian.org/LTS -------------------------------------------------------------------------Package : poppler Version : 0.71.0-5+deb10u1 CVE ID : CVE-2018-18897 CVE-2018-19058 CVE-2018-20650 CVE-2019-9903 CVE-2019-9959 CVE-2019-14494 CVE-2020-27778 CVE-2022-27337 CVE-2022-38784 Debian Bug : 913164 913177 917974 925264 941776 933812 1010695 1018971 Several security vulnerabilities have been discovered in Poppler, a PDF rendering library, that could lead to denial of service or possibly other unspecified impact when processing maliciously crafted documents. For Debian 10 buster, these problems have been fixed in version 0.71.0-5+deb10u1. We recommend that you upgrade your poppler packages. For the detailed security status of poppler please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/poppler Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Multiple security flaws in Poppler may lead to denial of service issues while handling harmful PDF files; it's advisable to upgrade.. Debian Security Advisory, Poppler Update, PDF Rendering Security, Denial of Service Threat. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 25, 2022 Critical Debian LTS
98

Red Hat: RHSA-2020-3977-01 Low: Evince And Poppler Security Update

An update for evince and poppler is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Low: evince and poppler security and bug fix update Advisory ID: RHSA-2020:3977-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:3977 Issue date: 2020-09-29 CVE Names: CVE-2019-14494 ==================================================================== 1. Summary: An update for evince and poppler is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Client (v. 7) - x86_64 Red Hat Enterprise Linux Client Optional (v. 7) - x86_64 Red Hat Enterprise Linux ComputeNode (v. 7) - x86_64 Red Hat Enterprise Linux ComputeNode Optional (v. 7) - x86_64 Red Hat Enterprise Linux Server (v. 7) - ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 7) - ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 7) - x86_64 Red Hat Enterprise Linux Workstation Optional (v. 7) - x86_64 3. Description: The evince packages provide a simple multi-page document viewer for Portable Document Format (PDF), PostScript (PS), Encapsulated PostScript (EPS) files, and, with additional back-ends, also the Device Independent File format (DVI) files. Poppler is a Portable Document Format (PDF) rendering library, used by applications such as Evince. Security Fix(es): * poppler: divide-by-zero in functionSplashOutputDev::tilingPatternFill in SplashOutputDev.cc (CVE-2019-14494) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.9 Release Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1610436 - Gtk-CRITICALs when scrolling in thumbnails bar in large file 1797453 - CVE-2019-14494 poppler: divide-by-zero in function SplashOutputDev::tilingPatternFill in SplashOutputDev.cc 6. Package List: Red Hat Enterprise Linux Client (v. 7): Source: evince-3.28.2-10.el7.src.rpm poppler-0.26.5-43.el7.src.rpm x86_64: evince-3.28.2-10.el7.x86_64.rpm evince-debuginfo-3.28.2-10.el7.i686.rpm evince-debuginfo-3.28.2-10.el7.x86_64.rpm evince-dvi-3.28.2-10.el7.x86_64.rpm evince-libs-3.28.2-10.el7.i686.rpm evince-libs-3.28.2-10.el7.x86_64.rpm evince-nautilus-3.28.2-10.el7.x86_64.rpm poppler-0.26.5-43.el7.i686.rpm poppler-0.26.5-43.el7.x86_64.rpm poppler-debuginfo-0.26.5-43.el7.i686.rpm poppler-debuginfo-0.26.5-43.el7.x86_64.rpm poppler-glib-0.26.5-43.el7.i686.rpm poppler-glib-0.26.5-43.el7.x86_64.rpm poppler-qt-0.26.5-43.el7.i686.rpm poppler-qt-0.26.5-43.el7.x86_64.rpm poppler-utils-0.26.5-43.el7.x86_64.rpm Red Hat Enterprise Linux Client Optional (v.7): x86_64: evince-browser-plugin-3.28.2-10.el7.x86_64.rpm evince-debuginfo-3.28.2-10.el7.i686.rpm evince-debuginfo-3.28.2-10.el7.x86_64.rpm evince-devel-3.28.2-10.el7.i686.rpm evince-devel-3.28.2-10.el7.x86_64.rpm poppler-cpp-0.26.5-43.el7.i686.rpm poppler-cpp-0.26.5-43.el7.x86_64.rpm poppler-cpp-devel-0.26.5-43.el7.i686.rpm poppler-cpp-devel-0.26.5-43.el7.x86_64.rpm poppler-debuginfo-0.26.5-43.el7.i686.rpm poppler-debuginfo-0.26.5-43.el7.x86_64.rpm poppler-demos-0.26.5-43.el7.x86_64.rpm poppler-devel-0.26.5-43.el7.i686.rpm poppler-devel-0.26.5-43.el7.x86_64.rpm poppler-glib-devel-0.26.5-43.el7.i686.rpm poppler-glib-devel-0.26.5-43.el7.x86_64.rpm poppler-qt-devel-0.26.5-43.el7.i686.rpm poppler-qt-devel-0.26.5-43.el7.x86_64.rpm Red Hat Enterprise Linux ComputeNode (v. 7): Source: poppler-0.26.5-43.el7.src.rpm x86_64: poppler-0.26.5-43.el7.i686.rpm poppler-0.26.5-43.el7.x86_64.rpm poppler-debuginfo-0.26.5-43.el7.i686.rpm poppler-debuginfo-0.26.5-43.el7.x86_64.rpm poppler-qt-0.26.5-43.el7.i686.rpm poppler-qt-0.26.5-43.el7.x86_64.rpm poppler-utils-0.26.5-43.el7.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional (v. 7): x86_64: poppler-cpp-0.26.5-43.el7.i686.rpm poppler-cpp-0.26.5-43.el7.x86_64.rpm poppler-cpp-devel-0.26.5-43.el7.i686.rpm poppler-cpp-devel-0.26.5-43.el7.x86_64.rpm poppler-debuginfo-0.26.5-43.el7.i686.rpm poppler-debuginfo-0.26.5-43.el7.x86_64.rpm poppler-demos-0.26.5-43.el7.x86_64.rpm poppler-devel-0.26.5-43.el7.i686.rpm poppler-devel-0.26.5-43.el7.x86_64.rpm poppler-glib-0.26.5-43.el7.i686.rpm poppler-glib-0.26.5-43.el7.x86_64.rpm poppler-glib-devel-0.26.5-43.el7.i686.rpm poppler-glib-devel-0.26.5-43.el7.x86_64.rpm poppler-qt-devel-0.26.5-43.el7.i686.rpm poppler-qt-devel-0.26.5-43.el7.x86_64.rpm Red Hat Enterprise Linux Server (v.7): Source: evince-3.28.2-10.el7.src.rpm poppler-0.26.5-43.el7.src.rpm ppc64: evince-3.28.2-10.el7.ppc64.rpm evince-debuginfo-3.28.2-10.el7.ppc.rpm evince-debuginfo-3.28.2-10.el7.ppc64.rpm evince-dvi-3.28.2-10.el7.ppc64.rpm evince-libs-3.28.2-10.el7.ppc.rpm evince-libs-3.28.2-10.el7.ppc64.rpm evince-nautilus-3.28.2-10.el7.ppc64.rpm poppler-0.26.5-43.el7.ppc.rpm poppler-0.26.5-43.el7.ppc64.rpm poppler-debuginfo-0.26.5-43.el7.ppc.rpm poppler-debuginfo-0.26.5-43.el7.ppc64.rpm poppler-glib-0.26.5-43.el7.ppc.rpm poppler-glib-0.26.5-43.el7.ppc64.rpm poppler-utils-0.26.5-43.el7.ppc64.rpm ppc64le: evince-3.28.2-10.el7.ppc64le.rpm evince-debuginfo-3.28.2-10.el7.ppc64le.rpm evince-dvi-3.28.2-10.el7.ppc64le.rpm evince-libs-3.28.2-10.el7.ppc64le.rpm evince-nautilus-3.28.2-10.el7.ppc64le.rpm poppler-0.26.5-43.el7.ppc64le.rpm poppler-debuginfo-0.26.5-43.el7.ppc64le.rpm poppler-glib-0.26.5-43.el7.ppc64le.rpm poppler-qt-0.26.5-43.el7.ppc64le.rpm poppler-utils-0.26.5-43.el7.ppc64le.rpm s390x: evince-3.28.2-10.el7.s390x.rpm evince-debuginfo-3.28.2-10.el7.s390.rpm evince-debuginfo-3.28.2-10.el7.s390x.rpm evince-dvi-3.28.2-10.el7.s390x.rpm evince-libs-3.28.2-10.el7.s390.rpm evince-libs-3.28.2-10.el7.s390x.rpm evince-nautilus-3.28.2-10.el7.s390x.rpm poppler-0.26.5-43.el7.s390.rpm poppler-0.26.5-43.el7.s390x.rpm poppler-debuginfo-0.26.5-43.el7.s390.rpm poppler-debuginfo-0.26.5-43.el7.s390x.rpm poppler-glib-0.26.5-43.el7.s390.rpm poppler-glib-0.26.5-43.el7.s390x.rpm poppler-utils-0.26.5-43.el7.s390x.rpm x86_64: evince-3.28.2-10.el7.x86_64.rpm evince-debuginfo-3.28.2-10.el7.i686.rpm evince-debuginfo-3.28.2-10.el7.x86_64.rpm evince-dvi-3.28.2-10.el7.x86_64.rpm evince-libs-3.28.2-10.el7.i686.rpm evince-libs-3.28.2-10.el7.x86_64.rpm evince-nautilus-3.28.2-10.el7.x86_64.rpm poppler-0.26.5-43.el7.i686.rpm poppler-0.26.5-43.el7.x86_64.rpm poppler-debuginfo-0.26.5-43.el7.i686.rpm poppler-debuginfo-0.26.5-43.el7.x86_64.rpm poppler-glib-0.26.5-43.el7.i686.rpm poppler-glib-0.26.5-43.el7.x86_64.rpm poppler-qt-0.26.5-43.el7.i686.rpm poppler-qt-0.26.5-43.el7.x86_64.rpm poppler-utils-0.26.5-43.el7.x86_64.rpm Red Hat Enterprise Linux Server Optional (v.7): ppc64: evince-browser-plugin-3.28.2-10.el7.ppc64.rpm evince-debuginfo-3.28.2-10.el7.ppc.rpm evince-debuginfo-3.28.2-10.el7.ppc64.rpm evince-devel-3.28.2-10.el7.ppc.rpm evince-devel-3.28.2-10.el7.ppc64.rpm poppler-cpp-0.26.5-43.el7.ppc.rpm poppler-cpp-0.26.5-43.el7.ppc64.rpm poppler-cpp-devel-0.26.5-43.el7.ppc.rpm poppler-cpp-devel-0.26.5-43.el7.ppc64.rpm poppler-debuginfo-0.26.5-43.el7.ppc.rpm poppler-debuginfo-0.26.5-43.el7.ppc64.rpm poppler-demos-0.26.5-43.el7.ppc64.rpm poppler-devel-0.26.5-43.el7.ppc.rpm poppler-devel-0.26.5-43.el7.ppc64.rpm poppler-glib-devel-0.26.5-43.el7.ppc.rpm poppler-glib-devel-0.26.5-43.el7.ppc64.rpm poppler-qt-0.26.5-43.el7.ppc.rpm poppler-qt-0.26.5-43.el7.ppc64.rpm poppler-qt-devel-0.26.5-43.el7.ppc.rpm poppler-qt-devel-0.26.5-43.el7.ppc64.rpm ppc64le: evince-browser-plugin-3.28.2-10.el7.ppc64le.rpm evince-debuginfo-3.28.2-10.el7.ppc64le.rpm evince-devel-3.28.2-10.el7.ppc64le.rpm poppler-cpp-0.26.5-43.el7.ppc64le.rpm poppler-cpp-devel-0.26.5-43.el7.ppc64le.rpm poppler-debuginfo-0.26.5-43.el7.ppc64le.rpm poppler-demos-0.26.5-43.el7.ppc64le.rpm poppler-devel-0.26.5-43.el7.ppc64le.rpm poppler-glib-devel-0.26.5-43.el7.ppc64le.rpm poppler-qt-devel-0.26.5-43.el7.ppc64le.rpm s390x: evince-browser-plugin-3.28.2-10.el7.s390x.rpm evince-debuginfo-3.28.2-10.el7.s390.rpm evince-debuginfo-3.28.2-10.el7.s390x.rpm evince-devel-3.28.2-10.el7.s390.rpm evince-devel-3.28.2-10.el7.s390x.rpm poppler-cpp-0.26.5-43.el7.s390.rpm poppler-cpp-0.26.5-43.el7.s390x.rpm poppler-cpp-devel-0.26.5-43.el7.s390.rpm poppler-cpp-devel-0.26.5-43.el7.s390x.rpm poppler-debuginfo-0.26.5-43.el7.s390.rpm poppler-debuginfo-0.26.5-43.el7.s390x.rpm poppler-demos-0.26.5-43.el7.s390x.rpm poppler-devel-0.26.5-43.el7.s390.rpm poppler-devel-0.26.5-43.el7.s390x.rpm poppler-glib-devel-0.26.5-43.el7.s390.rpm poppler-glib-devel-0.26.5-43.el7.s390x.rpm poppler-qt-0.26.5-43.el7.s390.rpm poppler-qt-0.26.5-43.el7.s390x.rpm poppler-qt-devel-0.26.5-43.el7.s390.rpm poppler-qt-devel-0.26.5-43.el7.s390x.rpm x86_64: evince-browser-plugin-3.28.2-10.el7.x86_64.rpm evince-debuginfo-3.28.2-10.el7.i686.rpm evince-debuginfo-3.28.2-10.el7.x86_64.rpm evince-devel-3.28.2-10.el7.i686.rpm evince-devel-3.28.2-10.el7.x86_64.rpm poppler-cpp-0.26.5-43.el7.i686.rpm poppler-cpp-0.26.5-43.el7.x86_64.rpm poppler-cpp-devel-0.26.5-43.el7.i686.rpm poppler-cpp-devel-0.26.5-43.el7.x86_64.rpm poppler-debuginfo-0.26.5-43.el7.i686.rpm poppler-debuginfo-0.26.5-43.el7.x86_64.rpm poppler-demos-0.26.5-43.el7.x86_64.rpm poppler-devel-0.26.5-43.el7.i686.rpm poppler-devel-0.26.5-43.el7.x86_64.rpm poppler-glib-devel-0.26.5-43.el7.i686.rpm poppler-glib-devel-0.26.5-43.el7.x86_64.rpm poppler-qt-devel-0.26.5-43.el7.i686.rpm poppler-qt-devel-0.26.5-43.el7.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 7): Source: evince-3.28.2-10.el7.src.rpm poppler-0.26.5-43.el7.src.rpm x86_64: evince-3.28.2-10.el7.x86_64.rpm evince-debuginfo-3.28.2-10.el7.i686.rpm evince-debuginfo-3.28.2-10.el7.x86_64.rpm evince-dvi-3.28.2-10.el7.x86_64.rpm evince-libs-3.28.2-10.el7.i686.rpm evince-libs-3.28.2-10.el7.x86_64.rpm evince-nautilus-3.28.2-10.el7.x86_64.rpm poppler-0.26.5-43.el7.i686.rpm poppler-0.26.5-43.el7.x86_64.rpm poppler-debuginfo-0.26.5-43.el7.i686.rpm poppler-debuginfo-0.26.5-43.el7.x86_64.rpm poppler-glib-0.26.5-43.el7.i686.rpm poppler-glib-0.26.5-43.el7.x86_64.rpm poppler-qt-0.26.5-43.el7.i686.rpm poppler-qt-0.26.5-43.el7.x86_64.rpm poppler-utils-0.26.5-43.el7.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v.7): x86_64: evince-browser-plugin-3.28.2-10.el7.x86_64.rpm evince-debuginfo-3.28.2-10.el7.i686.rpm evince-debuginfo-3.28.2-10.el7.x86_64.rpm evince-devel-3.28.2-10.el7.i686.rpm evince-devel-3.28.2-10.el7.x86_64.rpm poppler-cpp-0.26.5-43.el7.i686.rpm poppler-cpp-0.26.5-43.el7.x86_64.rpm poppler-cpp-devel-0.26.5-43.el7.i686.rpm poppler-cpp-devel-0.26.5-43.el7.x86_64.rpm poppler-debuginfo-0.26.5-43.el7.i686.rpm poppler-debuginfo-0.26.5-43.el7.x86_64.rpm poppler-demos-0.26.5-43.el7.x86_64.rpm poppler-devel-0.26.5-43.el7.i686.rpm poppler-devel-0.26.5-43.el7.x86_64.rpm poppler-glib-devel-0.26.5-43.el7.i686.rpm poppler-glib-devel-0.26.5-43.el7.x86_64.rpm poppler-qt-devel-0.26.5-43.el7.i686.rpm poppler-qt-devel-0.26.5-43.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2019-14494 https://access.redhat.com/security/updates/classification/#low https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/7.9_release_notes/index 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBX3OjytzjgjWX9erEAQg+WA//S9AxwyBHWq+hF+Bc8D7jLcma3rKBIJFY apkbmTL5CwKLV9DbFlryslfveYDMimhBEcHvGLqr+BjVUT2UamHv0vw1Fly7agJl ZnY4TS2Rc2/JJonqT61zH4NoCHrsMs47nnRXF6wAGVbNiG7GSdDYT8hcGKP8PAPo pW2S8BS+WEx99TmGZ4IMaf5NMEb9nVg8tKKpdcSLDaoxYYzTuY5dhnvxcDkAMDd4 eaN+9rpBBggtJsNCwq4QexVwwx2Ocl9KSPZyE6xpnpZkbDss8LerhvLr3HKKzJbM rwxWM87pfm/rVOuxXSLcOr9bNl+rv8eOeyx5tvClndcn41FayBlDGgrPw05GU+uP I6do8v7s+5dWNOYyIvxUb/qbB1/Sq3yHX17iQ7XmglQ1P7qqhhxQaFG26/tNhCnP UfkwK0EATl1EAMVQvyKVxQ5jiLS/i92YA/X4lHZHmgGLPbjYUKvxg3Enn5tZ1iP1 acSl6/tMfKdipWALKB62rSFjW3+ZFsWLeDlSA+BahPZVPJcvnuNU09JyUVwOrj/x dS9IAElPF1h/fQ1WnhIAf7Assh9sNJv4Ps4hd0cRWi1YfS8tkb55niLQk1fEfmFW WesSFDbLpqx/O5nfZQiyfgzrgSh/kH+0ekkQTFBA4hdMXiqBtdnEbgVbPV+wAnJA nIByLudtUGk=bPOk -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . New security patch released for Evince and Poppler in Red Hat. Minor risk mitigated from vulnerabilities. Urgent response recommended.. Evince Update, Poppler Security, Red Hat Enterprise, Linux Update, Security Fix. . Severity: Low. LinuxSecurity.com Team

Calendar%202 Sep 29, 2020 Low Red Hat
89

Fedora 31: FEDORA-2020-24ded2cd52 Critical: poppler CVE-2019-14494

Security fix for CVE-2019-14494.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-24ded2cd52 2020-02-11 01:13:14.425790 --------------------------------------------------------------------------------Name : poppler Product : Fedora 31 Version : 0.73.0 Release : 16.fc31 URL : http://poppler.freedesktop.org/ Summary : PDF rendering library Description : poppler is a PDF rendering library. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2019-14494. --------------------------------------------------------------------------------ChangeLog: * Tue Feb 4 2020 Marek Kasik - 0.73.0-16 - Fix crash on broken file in tilingPatternFill() - Resolves: #1797453 * Fri Dec 20 2019 Marek Kasik - 0.73.0-15 - Check scaled dimensions for 0 - Resolves: #1785416 --------------------------------------------------------------------------------References: [ 1 ] Bug #1797453 - CVE-2019-14494 poppler: divide-by-zero in function SplashOutputDev::tilingPatternFill in SplashOutputDev.cc https://bugzilla.redhat.com/show_bug.cgi?id=1797453 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-24ded2cd52' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. FedoraCode of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./ . --------------------------------------------------------------------------------Fedora Update Notifi. security, cve-2019-14494, -------------------------------------------------------------------. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Feb 10, 2020 Critical Fedora
172

Ubuntu 18.04 USN-3757-1 Moderate: Poppler Denial Of Service Exposure

poppler could be made to crash if it received specially crafted PDF file.. =========================================================================Ubuntu Security Notice USN-3757-1 August 29, 2018 poppler vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: poppler could be made to crash if it received specially crafted PDF file. Software Description: - poppler: PDF rendering library Details: Hosein Askari discovered that poppler incorrectly handled certain PDF files. An attacker could possible use this issue to cause a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: libpoppler73 0.62.0-2ubuntu2.2 poppler-utils 0.62.0-2ubuntu2.2 Ubuntu 16.04 LTS: libpoppler58 0.41.0-0ubuntu1.8 poppler-utils 0.41.0-0ubuntu1.8 Ubuntu 14.04 LTS: libpoppler44 0.24.5-2ubuntu4.12 poppler-utils 0.24.5-2ubuntu4.12 In general, a standard system update will make all the necessary changes. References: CVE-2018-13988 Package Information: https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.2 https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.8 https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.12 . Important patch released for Ubuntu remedying poppler security flaw resulting in service disruption. Safeguard your device immediately!. Poppler Vulnerability, Ubuntu Update, Denial of Service Fix. . LinuxSecurity.com Team

Calendar%202 Aug 29, 2018 Ubuntu
89

Fedora 28 Poppler Security Advisory: Critical CVE-2018-13988 Out Of Bounds

Security fix for CVE-2018-13988.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-c8c7d35b83 2018-07-31 18:00:51.600213 --------------------------------------------------------------------------------Name : poppler Product : Fedora 28 Version : 0.62.0 Release : 3.fc28 URL : http://poppler.freedesktop.org/ Summary : PDF rendering library Description : poppler is a PDF rendering library. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2018-13988. --------------------------------------------------------------------------------ChangeLog: * Thu Jul 26 2018 Marek Kasik - 0.62.0-3 - Fix crash when Object has negative number (CVE-2018-13988) - Resolves: #1607461 * Mon May 28 2018 Marek Kasik - 0.62.0-2 - Fix infinite recursion (CVE-2017-18267) - Resolves: #1578780 --------------------------------------------------------------------------------References: [ 1 ] Bug #1602838 - CVE-2018-13988 poppler: out of bounds read in pdfunite https://bugzilla.redhat.com/show_bug.cgi?id=1602838 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-c8c7d35b83' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct:https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./message/UFJ4HNVK37HLZUQTQNVGRX53R37JIFL2/ . Important security patch for Fedora 28 poppler focusing on CVE-2018-13988 to enhance PDF rendering reliability and protection.. Fedora Security Advisory, Poppler Update, Risk Mitigation for PDF. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jul 31, 2018 Critical Fedora
87

Debian Jessie: DSA-4079-2 Moderate: Poppler JBIG2 Rendering Fix

It was discovered that the poppler upload for the oldstable distribution (jessie), released as DSA-4079-1, did not correctly address CVE-2017-9776 and additionally caused regressions when rendering PDFs embedding JBIG2 streams. Updated packages are now available to correct . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4079-2 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/security/ Salvatore Bonaccorso April 12, 2018 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : poppler CVE ID : CVE-2017-9776 Debian Bug : 890826 It was discovered that the poppler upload for the oldstable distribution (jessie), released as DSA-4079-1, did not correctly address CVE-2017-9776 and additionally caused regressions when rendering PDFs embedding JBIG2 streams. Updated packages are now available to correct this issue. For the oldstable distribution (jessie), this problem has been fixed in version 0.26.5-2+deb8u4. We recommend that you upgrade your poppler packages. For the detailed security status of poppler please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/poppler Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: This email address is being protected from spambots. You need JavaScript enabled to view it. . The latest patch for poppler in Debian jessie mitigates CVE-2017-9776 and resolves existing rendering challenges associated with JBIG2 streams.. Debian Security, Poppler Update, JBIG2 Fix, DSA-4079-2. . LinuxSecurity.com Team

Calendar%202 Apr 12, 2018 Debian
89

Fedora 25: 2017-690eedcf41 Critical Poppler Null Pointer Threat

CVE-2017-7511 poppler: Null pointer dereference in pdfunite via crafted documents. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-690eedcf41 2017-06-05 19:34:06.752740 --------------------------------------------------------------------------------Name : poppler Product : Fedora 25 Version : 0.45.0 Release : 3.fc25 URL : http://poppler.freedesktop.org/ Summary : PDF rendering library Description : Poppler, a PDF rendering library, is a fork of the xpdf PDF viewer developed by Derek Noonburg of Glyph and Cog, LLC. --------------------------------------------------------------------------------Update Information: CVE-2017-7511 poppler: Null pointer dereference in pdfunite via crafted documents --------------------------------------------------------------------------------References: [ 1 ] Bug #1456828 - CVE-2017-7511 poppler: Null pointer dereference in pdfunite via crafted documents [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1456828 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade poppler' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. . Tackling CVE-2017-7511: Recent Fedora patch for poppler fixes a severe null dereference vulnerability in pdfunite.. Fedora Security Update, Poppler Library, Null PointerIssue, PDF Security, Software Update. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 06, 2017 Critical Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200