MGASA-2018-0290
Dashboard / Vulnerabilities / MGASA-2018-0290
MGASA-2018-0290
Summary: Updated poppler packages fix security vulnerability
Details: The updated packages fix security vulnerabilities: The FoFiType1C::cvtGlyph function in fofi/FoFiType1C.cc in Poppler through 0.64.0 allows remote attackers to cause a denial of service (infinite recursion) via a crafted PDF file, as demonstrated by pdftops. (CVE-2017-18267) There is a NULL pointer dereference in the AnnotPath::getCoordsLength function in Annot.h in an Ubuntu package for Poppler 0.24.5. A crafted input will lead to a remote denial of service attack. Later Ubuntu packages such as for Poppler 0.41.0 are not affected. (CVE-2018-10768)
References: https://advisories.mageia.org/MGASA-2018-0290.html, https://bugs.mageia.org/show_bug.cgi?id=23138, https://bugzilla.redhat.com/show_bug.cgi?id=1578777, https://usn.ubuntu.com/3647-1/
Affected packages
Package
Name: poppler
Purl: pkg:rpm/mageia/poppler?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
