SUSE-SU-2023:2838-1
Dashboard / Vulnerabilities / SUSE-SU-2023:2838-1
SUSE-SU-2023:2838-1
Summary: Security update for poppler
Details: This update for poppler fixes the following issues: - CVE-2022-27337: Fixed a logic error in the Hints::Hints function which can cause denial of service (bsc#1199272). - CVE-2018-21009: Fixed integer overflow in Parser:makeStream in Parser.cc (bsc#1149635). - CVE-2019-12293: Fixed heap-based buffer over-read in JPXStream:init in JPEG2000Stream.cc (bsc#1136105).
References: https://www.suse.com/support/update/announcement/2023/suse-su-20232838-1/, https://bugzilla.suse.com/1136105, https://bugzilla.suse.com/1149635, https://bugzilla.suse.com/1199272, https://www.suse.com/security/cve/CVE-2018-21009, https://www.suse.com/security/cve/CVE-2019-12293, https://www.suse.com/security/cve/CVE-2022-27337
Affected packages
Package
Name: poppler
Purl: pkg:rpm/opensuse/poppler&distro=openSUSE%20Leap%2015.4
Affected ranges
Type: ECOSYSTEM
Events:
