MGASA-2019-0117
Dashboard / Vulnerabilities / MGASA-2019-0117
MGASA-2019-0117
Summary: Updated poppler packages fix security vulnerabilities
Details: The updated poppler packages fix security vulnerabilities: In Poppler 0.72.0, PDFDoc::setup in PDFDoc.cc allows attackers to cause a denial-of-service (application crash caused by Object.h SIGABRT, because of a wrong return value from PDFDoc::setup) by crafting a PDF file in which an xref data structure is mishandled during extractPDFSubtype processing. (CVE-2018-20662) A heap-based buffer underwrite exists in ImageStream::getLine() located at Stream.cc in Poppler 0.74.0 that can (for example) be triggered by sending a crafted PDF file to the pdfimages binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. (CVE-2019-9200)
References: https://advisories.mageia.org/MGASA-2019-0117.html, https://bugs.mageia.org/show_bug.cgi?id=24495, https://usn.ubuntu.com/3905-1/
Affected packages
Package
Name: poppler
Purl: pkg:rpm/mageia/poppler?arch=source&distro=mageia-6
Affected ranges
Type: ECOSYSTEM
Events:
