MGASA-2017-0360
Dashboard / Vulnerabilities / MGASA-2017-0360
MGASA-2017-0360
Summary: Updated poppler packages fix security vulnerabilities
Details: In Poppler 0.59.0, a NULL Pointer Dereference exists in the XRef::parseEntry() function in XRef.cc via a crafted PDF document. (CVE-2017-14517) In Poppler 0.59.0, memory corruption occurs in a call to Object::streamGetChar in Object.h after a repeating series of Gfx::display, Gfx::go, Gfx::execOp, Gfx::opShowText, and Gfx::doShowText calls (aka a Gfx.cc infinite loop). (CVE-2017-14519) In Poppler 0.59.0, a floating point exception occurs in Splash::scaleImageYuXd() in Splash.cc, which may lead to a potential attack when handling malicious PDF files. (CVE-2017-14520)
References: https://advisories.mageia.org/MGASA-2017-0360.html, https://bugs.mageia.org/show_bug.cgi?id=21784, https://usn.ubuntu.com/usn/usn-3433-1/, https://bugzilla.redhat.com/show_bug.cgi?id=1494582
Affected packages
Package
Name: poppler
Purl: pkg:rpm/mageia/poppler?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
