SUSE-SU-2018:2481-1
Dashboard / Vulnerabilities / SUSE-SU-2018:2481-1
SUSE-SU-2018:2481-1
Summary: Security update for podofo
Details: This update for podofo fixes the following issues: - CVE-2017-5852: The PoDoFo::PdfPage::GetInheritedKeyFromObject function allowed remote attackers to cause a denial of service (infinite loop) via a crafted file (bsc#1023067). - CVE-2017-5853: Integer overflow allowed remote attackers to have unspecified impact via a crafted file (bsc#1023069). - CVE-2017-5854: Prevent NULL pointer dereference that allowed remote attackers to cause a denial of service via a crafted file (bsc#1023070). - CVE-2017-5855: The PoDoFo::PdfParser::ReadXRefSubsection function allowed remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file (bsc#1023071). - CVE-2017-5886: Prevent heap-based buffer overflow in the PoDoFo::PdfTokenizer::GetNextToken function that allowed remote attackers to have unspecified impact via a crafted file (bsc#1023380). - CVE-2017-6847: The PoDoFo::PdfVariant::DelayedLoad function allowed remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file (bsc#1027778). - CVE-2017-6844: Buffer overflow in the PoDoFo::PdfParser::ReadXRefSubsection function allowed remote attackers to have unspecified impact via a crafted file (bsc#1027782). - CVE-2017-6840: The ColorChanger::GetColorFromStack function allowed remote attackers to cause a denial of service (invalid read) via a crafted file (bsc#1027787). - CVE-2017-7378: The PoDoFo::PdfPainter::ExpandTabs function allowed remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted PDF document (bsc#1032017). - CVE-2017-7379: The PoDoFo::PdfSimpleEncoding::ConvertToEncoding function allowed remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted PDF document (bsc#1032018). - CVE-2017-7380: Prevent NULL pointer dereference that allowed remote attackers to cause a denial of service via a crafted PDF document (bsc#1032019). - CVE-2017-7994: The function TextExtractor::ExtractText allowed remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PDF document (bsc#1035534). - CVE-2017-8054: The function PdfPagesTree::GetPageNodeFromArray allowed remote attackers to cause a denial of service (infinite recursion and application crash) via a crafted PDF document (bsc#1035596). - CVE-2017-8787: The PoDoFo::PdfXRefStreamParserObject::ReadXRefStreamEntry function allowed remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted PDF file (bsc#1037739). - CVE-2018-5308: Properly validate memcpy arguments in the PdfMemoryOutputStream::Write function to prevent remote attackers from causing a denial-of-service or possibly have unspecified other impact via a crafted pdf file (bsc#1075772). - CVE-2018-8001: Prevent heap-based buffer over-read vulnerability in UnescapeName() that allowed remote attackers to cause a denial-of-service or possibly unspecified other impact via a crafted pdf file (bsc#1084894).
References: https://www.suse.com/support/update/announcement/2018/suse-su-20182481-1/, https://bugzilla.suse.com/1023067, https://bugzilla.suse.com/1023069, https://bugzilla.suse.com/1023070, https://bugzilla.suse.com/1023071, https://bugzilla.suse.com/1023380, https://bugzilla.suse.com/1027778, https://bugzilla.suse.com/1027782, https://bugzilla.suse.com/1027787, https://bugzilla.suse.com/1032017, https://bugzilla.suse.com/1032018, https://bugzilla.suse.com/1032019, https://bugzilla.suse.com/1035534, https://bugzilla.suse.com/1035596, https://bugzilla.suse.com/1037739, https://bugzilla.suse.com/1075772, https://bugzilla.suse.com/1084894, https://www.suse.com/security/cve/CVE-2017-5852, https://www.suse.com/security/cve/CVE-2017-5853, https://www.suse.com/security/cve/CVE-2017-5854, https://www.suse.com/security/cve/CVE-2017-5855, https://www.suse.com/security/cve/CVE-2017-5886, https://www.suse.com/security/cve/CVE-2017-6840, https://www.suse.com/security/cve/CVE-2017-6844, https://www.suse.com/security/cve/CVE-2017-6847, https://www.suse.com/security/cve/CVE-2017-7378, https://www.suse.com/security/cve/CVE-2017-7379, https://www.suse.com/security/cve/CVE-2017-7380, https://www.suse.com/security/cve/CVE-2017-7994, https://www.suse.com/security/cve/CVE-2017-8054, https://www.suse.com/security/cve/CVE-2017-8787, https://www.suse.com/security/cve/CVE-2018-5308, https://www.suse.com/security/cve/CVE-2018-8001
Affected packages
Package
Name: podofo
Purl: pkg:rpm/suse/podofo&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3
Affected ranges
Type: ECOSYSTEM
Events:
