Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
poppler could be made to denial of service if it opened a specially crafted PDF.. ========================================================================== Ubuntu Security Notice USN-6915-1 July 24, 2024 poppler vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: poppler could be made to denial of service if it opened a specially crafted PDF. Software Description: - poppler: PDF rendering library Details: It was discovered that poppler incorrectly handled certain malformed PDF. An attacker could possibly use this issue to cause a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS libpoppler134 24.02.0-1ubuntu9.1 poppler-utils 24.02.0-1ubuntu9.1 Ubuntu 22.04 LTS libpoppler118 22.02.0-2ubuntu0.5 poppler-utils 22.02.0-2ubuntu0.5 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6915-1 CVE-2024-6239 Package Information: https://launchpad.net/ubuntu/+source/poppler/24.02.0-1ubuntu9.1 https://launchpad.net/ubuntu/+source/poppler/22.02.0-2ubuntu0.5 . The Ubuntu Security Notice USN-6915-1 concerns a critical vulnerability in poppler that could lead to denial of service attacks arising from incorrectly formatted PDFs.. Ubuntu Security Notice, Poppler PDF, Denial of Service, Security Updates. . LinuxSecurity.com Team
Several security vulnerabilities have been discovered in Poppler, a PDF rendering library, that could lead to denial of service or possibly other unspecified impact when processing maliciously crafted documents. . -------------------------------------------------------------------------Debian LTS Advisory DLA-3120-1
An update for evince and poppler is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Low: evince and poppler security and bug fix update Advisory ID: RHSA-2020:3977-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2020:3977 Issue date: 2020-09-29 CVE Names: CVE-2019-14494 ==================================================================== 1. Summary: An update for evince and poppler is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Low. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Client (v. 7) - x86_64 Red Hat Enterprise Linux Client Optional (v. 7) - x86_64 Red Hat Enterprise Linux ComputeNode (v. 7) - x86_64 Red Hat Enterprise Linux ComputeNode Optional (v. 7) - x86_64 Red Hat Enterprise Linux Server (v. 7) - ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 7) - ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 7) - x86_64 Red Hat Enterprise Linux Workstation Optional (v. 7) - x86_64 3. Description: The evince packages provide a simple multi-page document viewer for Portable Document Format (PDF), PostScript (PS), Encapsulated PostScript (EPS) files, and, with additional back-ends, also the Device Independent File format (DVI) files. Poppler is a Portable Document Format (PDF) rendering library, used by applications such as Evince. Security Fix(es): * poppler: divide-by-zero in functionSplashOutputDev::tilingPatternFill in SplashOutputDev.cc (CVE-2019-14494) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.9 Release Notes linked from the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1610436 - Gtk-CRITICALs when scrolling in thumbnails bar in large file 1797453 - CVE-2019-14494 poppler: divide-by-zero in function SplashOutputDev::tilingPatternFill in SplashOutputDev.cc 6. Package List: Red Hat Enterprise Linux Client (v. 7): Source: evince-3.28.2-10.el7.src.rpm poppler-0.26.5-43.el7.src.rpm x86_64: evince-3.28.2-10.el7.x86_64.rpm evince-debuginfo-3.28.2-10.el7.i686.rpm evince-debuginfo-3.28.2-10.el7.x86_64.rpm evince-dvi-3.28.2-10.el7.x86_64.rpm evince-libs-3.28.2-10.el7.i686.rpm evince-libs-3.28.2-10.el7.x86_64.rpm evince-nautilus-3.28.2-10.el7.x86_64.rpm poppler-0.26.5-43.el7.i686.rpm poppler-0.26.5-43.el7.x86_64.rpm poppler-debuginfo-0.26.5-43.el7.i686.rpm poppler-debuginfo-0.26.5-43.el7.x86_64.rpm poppler-glib-0.26.5-43.el7.i686.rpm poppler-glib-0.26.5-43.el7.x86_64.rpm poppler-qt-0.26.5-43.el7.i686.rpm poppler-qt-0.26.5-43.el7.x86_64.rpm poppler-utils-0.26.5-43.el7.x86_64.rpm Red Hat Enterprise Linux Client Optional (v.7): x86_64: evince-browser-plugin-3.28.2-10.el7.x86_64.rpm evince-debuginfo-3.28.2-10.el7.i686.rpm evince-debuginfo-3.28.2-10.el7.x86_64.rpm evince-devel-3.28.2-10.el7.i686.rpm evince-devel-3.28.2-10.el7.x86_64.rpm poppler-cpp-0.26.5-43.el7.i686.rpm poppler-cpp-0.26.5-43.el7.x86_64.rpm poppler-cpp-devel-0.26.5-43.el7.i686.rpm poppler-cpp-devel-0.26.5-43.el7.x86_64.rpm poppler-debuginfo-0.26.5-43.el7.i686.rpm poppler-debuginfo-0.26.5-43.el7.x86_64.rpm poppler-demos-0.26.5-43.el7.x86_64.rpm poppler-devel-0.26.5-43.el7.i686.rpm poppler-devel-0.26.5-43.el7.x86_64.rpm poppler-glib-devel-0.26.5-43.el7.i686.rpm poppler-glib-devel-0.26.5-43.el7.x86_64.rpm poppler-qt-devel-0.26.5-43.el7.i686.rpm poppler-qt-devel-0.26.5-43.el7.x86_64.rpm Red Hat Enterprise Linux ComputeNode (v. 7): Source: poppler-0.26.5-43.el7.src.rpm x86_64: poppler-0.26.5-43.el7.i686.rpm poppler-0.26.5-43.el7.x86_64.rpm poppler-debuginfo-0.26.5-43.el7.i686.rpm poppler-debuginfo-0.26.5-43.el7.x86_64.rpm poppler-qt-0.26.5-43.el7.i686.rpm poppler-qt-0.26.5-43.el7.x86_64.rpm poppler-utils-0.26.5-43.el7.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional (v. 7): x86_64: poppler-cpp-0.26.5-43.el7.i686.rpm poppler-cpp-0.26.5-43.el7.x86_64.rpm poppler-cpp-devel-0.26.5-43.el7.i686.rpm poppler-cpp-devel-0.26.5-43.el7.x86_64.rpm poppler-debuginfo-0.26.5-43.el7.i686.rpm poppler-debuginfo-0.26.5-43.el7.x86_64.rpm poppler-demos-0.26.5-43.el7.x86_64.rpm poppler-devel-0.26.5-43.el7.i686.rpm poppler-devel-0.26.5-43.el7.x86_64.rpm poppler-glib-0.26.5-43.el7.i686.rpm poppler-glib-0.26.5-43.el7.x86_64.rpm poppler-glib-devel-0.26.5-43.el7.i686.rpm poppler-glib-devel-0.26.5-43.el7.x86_64.rpm poppler-qt-devel-0.26.5-43.el7.i686.rpm poppler-qt-devel-0.26.5-43.el7.x86_64.rpm Red Hat Enterprise Linux Server (v.7): Source: evince-3.28.2-10.el7.src.rpm poppler-0.26.5-43.el7.src.rpm ppc64: evince-3.28.2-10.el7.ppc64.rpm evince-debuginfo-3.28.2-10.el7.ppc.rpm evince-debuginfo-3.28.2-10.el7.ppc64.rpm evince-dvi-3.28.2-10.el7.ppc64.rpm evince-libs-3.28.2-10.el7.ppc.rpm evince-libs-3.28.2-10.el7.ppc64.rpm evince-nautilus-3.28.2-10.el7.ppc64.rpm poppler-0.26.5-43.el7.ppc.rpm poppler-0.26.5-43.el7.ppc64.rpm poppler-debuginfo-0.26.5-43.el7.ppc.rpm poppler-debuginfo-0.26.5-43.el7.ppc64.rpm poppler-glib-0.26.5-43.el7.ppc.rpm poppler-glib-0.26.5-43.el7.ppc64.rpm poppler-utils-0.26.5-43.el7.ppc64.rpm ppc64le: evince-3.28.2-10.el7.ppc64le.rpm evince-debuginfo-3.28.2-10.el7.ppc64le.rpm evince-dvi-3.28.2-10.el7.ppc64le.rpm evince-libs-3.28.2-10.el7.ppc64le.rpm evince-nautilus-3.28.2-10.el7.ppc64le.rpm poppler-0.26.5-43.el7.ppc64le.rpm poppler-debuginfo-0.26.5-43.el7.ppc64le.rpm poppler-glib-0.26.5-43.el7.ppc64le.rpm poppler-qt-0.26.5-43.el7.ppc64le.rpm poppler-utils-0.26.5-43.el7.ppc64le.rpm s390x: evince-3.28.2-10.el7.s390x.rpm evince-debuginfo-3.28.2-10.el7.s390.rpm evince-debuginfo-3.28.2-10.el7.s390x.rpm evince-dvi-3.28.2-10.el7.s390x.rpm evince-libs-3.28.2-10.el7.s390.rpm evince-libs-3.28.2-10.el7.s390x.rpm evince-nautilus-3.28.2-10.el7.s390x.rpm poppler-0.26.5-43.el7.s390.rpm poppler-0.26.5-43.el7.s390x.rpm poppler-debuginfo-0.26.5-43.el7.s390.rpm poppler-debuginfo-0.26.5-43.el7.s390x.rpm poppler-glib-0.26.5-43.el7.s390.rpm poppler-glib-0.26.5-43.el7.s390x.rpm poppler-utils-0.26.5-43.el7.s390x.rpm x86_64: evince-3.28.2-10.el7.x86_64.rpm evince-debuginfo-3.28.2-10.el7.i686.rpm evince-debuginfo-3.28.2-10.el7.x86_64.rpm evince-dvi-3.28.2-10.el7.x86_64.rpm evince-libs-3.28.2-10.el7.i686.rpm evince-libs-3.28.2-10.el7.x86_64.rpm evince-nautilus-3.28.2-10.el7.x86_64.rpm poppler-0.26.5-43.el7.i686.rpm poppler-0.26.5-43.el7.x86_64.rpm poppler-debuginfo-0.26.5-43.el7.i686.rpm poppler-debuginfo-0.26.5-43.el7.x86_64.rpm poppler-glib-0.26.5-43.el7.i686.rpm poppler-glib-0.26.5-43.el7.x86_64.rpm poppler-qt-0.26.5-43.el7.i686.rpm poppler-qt-0.26.5-43.el7.x86_64.rpm poppler-utils-0.26.5-43.el7.x86_64.rpm Red Hat Enterprise Linux Server Optional (v.7): ppc64: evince-browser-plugin-3.28.2-10.el7.ppc64.rpm evince-debuginfo-3.28.2-10.el7.ppc.rpm evince-debuginfo-3.28.2-10.el7.ppc64.rpm evince-devel-3.28.2-10.el7.ppc.rpm evince-devel-3.28.2-10.el7.ppc64.rpm poppler-cpp-0.26.5-43.el7.ppc.rpm poppler-cpp-0.26.5-43.el7.ppc64.rpm poppler-cpp-devel-0.26.5-43.el7.ppc.rpm poppler-cpp-devel-0.26.5-43.el7.ppc64.rpm poppler-debuginfo-0.26.5-43.el7.ppc.rpm poppler-debuginfo-0.26.5-43.el7.ppc64.rpm poppler-demos-0.26.5-43.el7.ppc64.rpm poppler-devel-0.26.5-43.el7.ppc.rpm poppler-devel-0.26.5-43.el7.ppc64.rpm poppler-glib-devel-0.26.5-43.el7.ppc.rpm poppler-glib-devel-0.26.5-43.el7.ppc64.rpm poppler-qt-0.26.5-43.el7.ppc.rpm poppler-qt-0.26.5-43.el7.ppc64.rpm poppler-qt-devel-0.26.5-43.el7.ppc.rpm poppler-qt-devel-0.26.5-43.el7.ppc64.rpm ppc64le: evince-browser-plugin-3.28.2-10.el7.ppc64le.rpm evince-debuginfo-3.28.2-10.el7.ppc64le.rpm evince-devel-3.28.2-10.el7.ppc64le.rpm poppler-cpp-0.26.5-43.el7.ppc64le.rpm poppler-cpp-devel-0.26.5-43.el7.ppc64le.rpm poppler-debuginfo-0.26.5-43.el7.ppc64le.rpm poppler-demos-0.26.5-43.el7.ppc64le.rpm poppler-devel-0.26.5-43.el7.ppc64le.rpm poppler-glib-devel-0.26.5-43.el7.ppc64le.rpm poppler-qt-devel-0.26.5-43.el7.ppc64le.rpm s390x: evince-browser-plugin-3.28.2-10.el7.s390x.rpm evince-debuginfo-3.28.2-10.el7.s390.rpm evince-debuginfo-3.28.2-10.el7.s390x.rpm evince-devel-3.28.2-10.el7.s390.rpm evince-devel-3.28.2-10.el7.s390x.rpm poppler-cpp-0.26.5-43.el7.s390.rpm poppler-cpp-0.26.5-43.el7.s390x.rpm poppler-cpp-devel-0.26.5-43.el7.s390.rpm poppler-cpp-devel-0.26.5-43.el7.s390x.rpm poppler-debuginfo-0.26.5-43.el7.s390.rpm poppler-debuginfo-0.26.5-43.el7.s390x.rpm poppler-demos-0.26.5-43.el7.s390x.rpm poppler-devel-0.26.5-43.el7.s390.rpm poppler-devel-0.26.5-43.el7.s390x.rpm poppler-glib-devel-0.26.5-43.el7.s390.rpm poppler-glib-devel-0.26.5-43.el7.s390x.rpm poppler-qt-0.26.5-43.el7.s390.rpm poppler-qt-0.26.5-43.el7.s390x.rpm poppler-qt-devel-0.26.5-43.el7.s390.rpm poppler-qt-devel-0.26.5-43.el7.s390x.rpm x86_64: evince-browser-plugin-3.28.2-10.el7.x86_64.rpm evince-debuginfo-3.28.2-10.el7.i686.rpm evince-debuginfo-3.28.2-10.el7.x86_64.rpm evince-devel-3.28.2-10.el7.i686.rpm evince-devel-3.28.2-10.el7.x86_64.rpm poppler-cpp-0.26.5-43.el7.i686.rpm poppler-cpp-0.26.5-43.el7.x86_64.rpm poppler-cpp-devel-0.26.5-43.el7.i686.rpm poppler-cpp-devel-0.26.5-43.el7.x86_64.rpm poppler-debuginfo-0.26.5-43.el7.i686.rpm poppler-debuginfo-0.26.5-43.el7.x86_64.rpm poppler-demos-0.26.5-43.el7.x86_64.rpm poppler-devel-0.26.5-43.el7.i686.rpm poppler-devel-0.26.5-43.el7.x86_64.rpm poppler-glib-devel-0.26.5-43.el7.i686.rpm poppler-glib-devel-0.26.5-43.el7.x86_64.rpm poppler-qt-devel-0.26.5-43.el7.i686.rpm poppler-qt-devel-0.26.5-43.el7.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 7): Source: evince-3.28.2-10.el7.src.rpm poppler-0.26.5-43.el7.src.rpm x86_64: evince-3.28.2-10.el7.x86_64.rpm evince-debuginfo-3.28.2-10.el7.i686.rpm evince-debuginfo-3.28.2-10.el7.x86_64.rpm evince-dvi-3.28.2-10.el7.x86_64.rpm evince-libs-3.28.2-10.el7.i686.rpm evince-libs-3.28.2-10.el7.x86_64.rpm evince-nautilus-3.28.2-10.el7.x86_64.rpm poppler-0.26.5-43.el7.i686.rpm poppler-0.26.5-43.el7.x86_64.rpm poppler-debuginfo-0.26.5-43.el7.i686.rpm poppler-debuginfo-0.26.5-43.el7.x86_64.rpm poppler-glib-0.26.5-43.el7.i686.rpm poppler-glib-0.26.5-43.el7.x86_64.rpm poppler-qt-0.26.5-43.el7.i686.rpm poppler-qt-0.26.5-43.el7.x86_64.rpm poppler-utils-0.26.5-43.el7.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v.7): x86_64: evince-browser-plugin-3.28.2-10.el7.x86_64.rpm evince-debuginfo-3.28.2-10.el7.i686.rpm evince-debuginfo-3.28.2-10.el7.x86_64.rpm evince-devel-3.28.2-10.el7.i686.rpm evince-devel-3.28.2-10.el7.x86_64.rpm poppler-cpp-0.26.5-43.el7.i686.rpm poppler-cpp-0.26.5-43.el7.x86_64.rpm poppler-cpp-devel-0.26.5-43.el7.i686.rpm poppler-cpp-devel-0.26.5-43.el7.x86_64.rpm poppler-debuginfo-0.26.5-43.el7.i686.rpm poppler-debuginfo-0.26.5-43.el7.x86_64.rpm poppler-demos-0.26.5-43.el7.x86_64.rpm poppler-devel-0.26.5-43.el7.i686.rpm poppler-devel-0.26.5-43.el7.x86_64.rpm poppler-glib-devel-0.26.5-43.el7.i686.rpm poppler-glib-devel-0.26.5-43.el7.x86_64.rpm poppler-qt-devel-0.26.5-43.el7.i686.rpm poppler-qt-devel-0.26.5-43.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2019-14494 https://access.redhat.com/security/updates/classification/#low https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/7.9_release_notes/index 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2020 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBX3OjytzjgjWX9erEAQg+WA//S9AxwyBHWq+hF+Bc8D7jLcma3rKBIJFY apkbmTL5CwKLV9DbFlryslfveYDMimhBEcHvGLqr+BjVUT2UamHv0vw1Fly7agJl ZnY4TS2Rc2/JJonqT61zH4NoCHrsMs47nnRXF6wAGVbNiG7GSdDYT8hcGKP8PAPo pW2S8BS+WEx99TmGZ4IMaf5NMEb9nVg8tKKpdcSLDaoxYYzTuY5dhnvxcDkAMDd4 eaN+9rpBBggtJsNCwq4QexVwwx2Ocl9KSPZyE6xpnpZkbDss8LerhvLr3HKKzJbM rwxWM87pfm/rVOuxXSLcOr9bNl+rv8eOeyx5tvClndcn41FayBlDGgrPw05GU+uP I6do8v7s+5dWNOYyIvxUb/qbB1/Sq3yHX17iQ7XmglQ1P7qqhhxQaFG26/tNhCnP UfkwK0EATl1EAMVQvyKVxQ5jiLS/i92YA/X4lHZHmgGLPbjYUKvxg3Enn5tZ1iP1 acSl6/tMfKdipWALKB62rSFjW3+ZFsWLeDlSA+BahPZVPJcvnuNU09JyUVwOrj/x dS9IAElPF1h/fQ1WnhIAf7Assh9sNJv4Ps4hd0cRWi1YfS8tkb55niLQk1fEfmFW WesSFDbLpqx/O5nfZQiyfgzrgSh/kH+0ekkQTFBA4hdMXiqBtdnEbgVbPV+wAnJA nIByLudtUGk=bPOk -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Security fix for CVE-2019-14494.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-24ded2cd52 2020-02-11 01:13:14.425790 --------------------------------------------------------------------------------Name : poppler Product : Fedora 31 Version : 0.73.0 Release : 16.fc31 URL : http://poppler.freedesktop.org/ Summary : PDF rendering library Description : poppler is a PDF rendering library. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2019-14494. --------------------------------------------------------------------------------ChangeLog: * Tue Feb 4 2020 Marek Kasik - 0.73.0-16 - Fix crash on broken file in tilingPatternFill() - Resolves: #1797453 * Fri Dec 20 2019 Marek Kasik - 0.73.0-15 - Check scaled dimensions for 0 - Resolves: #1785416 --------------------------------------------------------------------------------References: [ 1 ] Bug #1797453 - CVE-2019-14494 poppler: divide-by-zero in function SplashOutputDev::tilingPatternFill in SplashOutputDev.cc https://bugzilla.redhat.com/show_bug.cgi?id=1797453 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-24ded2cd52' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
poppler could be made to crash if it received specially crafted PDF file.. =========================================================================Ubuntu Security Notice USN-3757-1 August 29, 2018 poppler vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: poppler could be made to crash if it received specially crafted PDF file. Software Description: - poppler: PDF rendering library Details: Hosein Askari discovered that poppler incorrectly handled certain PDF files. An attacker could possible use this issue to cause a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: libpoppler73 0.62.0-2ubuntu2.2 poppler-utils 0.62.0-2ubuntu2.2 Ubuntu 16.04 LTS: libpoppler58 0.41.0-0ubuntu1.8 poppler-utils 0.41.0-0ubuntu1.8 Ubuntu 14.04 LTS: libpoppler44 0.24.5-2ubuntu4.12 poppler-utils 0.24.5-2ubuntu4.12 In general, a standard system update will make all the necessary changes. References: CVE-2018-13988 Package Information: https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.2 https://launchpad.net/ubuntu/+source/poppler/0.41.0-0ubuntu1.8 https://launchpad.net/ubuntu/+source/poppler/0.24.5-2ubuntu4.12 . Important patch released for Ubuntu remedying poppler security flaw resulting in service disruption. Safeguard your device immediately!. Poppler Vulnerability, Ubuntu Update, Denial of Service Fix. . LinuxSecurity.com Team
Security fix for CVE-2018-13988.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-c8c7d35b83 2018-07-31 18:00:51.600213 --------------------------------------------------------------------------------Name : poppler Product : Fedora 28 Version : 0.62.0 Release : 3.fc28 URL : http://poppler.freedesktop.org/ Summary : PDF rendering library Description : poppler is a PDF rendering library. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2018-13988. --------------------------------------------------------------------------------ChangeLog: * Thu Jul 26 2018 Marek Kasik - 0.62.0-3 - Fix crash when Object has negative number (CVE-2018-13988) - Resolves: #1607461 * Mon May 28 2018 Marek Kasik - 0.62.0-2 - Fix infinite recursion (CVE-2017-18267) - Resolves: #1578780 --------------------------------------------------------------------------------References: [ 1 ] Bug #1602838 - CVE-2018-13988 poppler: out of bounds read in pdfunite https://bugzilla.redhat.com/show_bug.cgi?id=1602838 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-c8c7d35b83' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
It was discovered that the poppler upload for the oldstable distribution (jessie), released as DSA-4079-1, did not correctly address CVE-2017-9776 and additionally caused regressions when rendering PDFs embedding JBIG2 streams. Updated packages are now available to correct . - ------------------------------------------------------------------------- Debian Security Advisory DSA-4079-2
CVE-2017-7511 poppler: Null pointer dereference in pdfunite via crafted documents. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2017-690eedcf41 2017-06-05 19:34:06.752740 --------------------------------------------------------------------------------Name : poppler Product : Fedora 25 Version : 0.45.0 Release : 3.fc25 URL : http://poppler.freedesktop.org/ Summary : PDF rendering library Description : Poppler, a PDF rendering library, is a fork of the xpdf PDF viewer developed by Derek Noonburg of Glyph and Cog, LLC. --------------------------------------------------------------------------------Update Information: CVE-2017-7511 poppler: Null pointer dereference in pdfunite via crafted documents --------------------------------------------------------------------------------References: [ 1 ] Bug #1456828 - CVE-2017-7511 poppler: Null pointer dereference in pdfunite via crafted documents [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1456828 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade poppler' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.