SUSE-SU-2018:3066-1
Dashboard / Vulnerabilities / SUSE-SU-2018:3066-1
SUSE-SU-2018:3066-1
Summary: Security update for qpdf
Details: This update for qpdf fixes the following issues: qpdf was updated to 7.1.1. Security issues fixed: - CVE-2017-11627: A stack-consumption vulnerability which allows attackers to cause DoS (bsc#1050577). - CVE-2017-11625: A stack-consumption vulnerability which allows attackers to cause DoS (bsc#1050579). - CVE-2017-11626: A stack-consumption vulnerability which allows attackers to cause DoS (bsc#1050578). - CVE-2017-11624: A stack-consumption vulnerability which allows attackers to cause DoS (bsc#1050581). - CVE-2017-12595: Stack overflow when processing deeply nested arrays and dictionaries (bsc#1055960). - CVE-2017-9209: Remote attackers can cause a denial of service (infinite recursion and stack consumption) via a crafted PDF document (bsc#1040312). - CVE-2017-9210: Remote attackers can cause a denial of service (infinite recursion and stack consumption) via a crafted PDF document (bsc#1040313). - CVE-2017-9208: Remote attackers can cause a denial of service (infinite recursion and stack consumption) via a crafted PDF document (bsc#1040311). * Check release notes for detailed bug fixes. * http://qpdf.sourceforge.net/files/qpdf-manual.html#ref.release-notes
References: https://www.suse.com/support/update/announcement/2018/suse-su-20183066-1/, https://bugzilla.suse.com/1040311, https://bugzilla.suse.com/1040312, https://bugzilla.suse.com/1040313, https://bugzilla.suse.com/1050577, https://bugzilla.suse.com/1050578, https://bugzilla.suse.com/1050579, https://bugzilla.suse.com/1050581, https://bugzilla.suse.com/1055960, https://www.suse.com/security/cve/CVE-2017-11624, https://www.suse.com/security/cve/CVE-2017-11625, https://www.suse.com/security/cve/CVE-2017-11626, https://www.suse.com/security/cve/CVE-2017-11627, https://www.suse.com/security/cve/CVE-2017-12595, https://www.suse.com/security/cve/CVE-2017-9208, https://www.suse.com/security/cve/CVE-2017-9209, https://www.suse.com/security/cve/CVE-2017-9210
Affected packages
Package
Name: cups-filters
Purl: pkg:rpm/suse/cups-filters&distro=SUSE%20OpenStack%20Cloud%207
Affected ranges
Type: ECOSYSTEM
Events:
