MGASA-2017-0402
Dashboard / Vulnerabilities / MGASA-2017-0402
MGASA-2017-0402
Summary: Updated poppler packages fix security vulnerabilities
Details: In Poppler 0.59.0, a NULL Pointer Dereference exists in the SplashOutputDev::type3D0() function in SplashOutputDev.cc via a crafted PDF document. (CVE-2017-14927) The FoFiType1C::convertToType0 function in FoFiType1C.cc in Poppler 0.59.0 has a heap-based buffer over-read vulnerability if an out-of-bounds font dictionary index is encountered, which allows an attacker to launch a denial of service attack. (CVE-2017-14976) In Poppler 0.59.0, a NULL Pointer Dereference exists in the GfxImageColorMap::getGrayLine() function in GfxState.cc via a crafted PDF document. (CVE-2017-15565)
References: https://advisories.mageia.org/MGASA-2017-0402.html, https://bugs.mageia.org/show_bug.cgi?id=21939, https://bugzilla.redhat.com/show_bug.cgi?id=1500345, https://bugzilla.redhat.com/show_bug.cgi?id=1500324, https://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-14927.html, https://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-14976.html, https://usn.ubuntu.com/usn/usn-3467-1/
Affected packages
Package
Name: poppler
Purl: pkg:rpm/mageia/poppler?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
