SUSE-SU-2023:2906-1
Dashboard / Vulnerabilities / SUSE-SU-2023:2906-1
SUSE-SU-2023:2906-1
Summary: Security update for poppler
Details: This update for poppler fixes the following issues: - CVE-2022-27337: Fixed a logic error in the Hints::Hints function which can cause denial of service (bsc#1199272). - CVE-2018-21009: Fixed integer overflow in Parser:makeStream in Parser.cc (bsc#1149635). - CVE-2018-20481: Fixed memory leak in GfxColorSpace:setDisplayProfile in GfxState.cc (bsc#1114966). - CVE-2019-7310: Fixed a heap-based buffer over-read allows remote attackers to cause DOS via a special crafted PDF (bsc#1124150). - CVE-2018-13988: Fixed buffer overflow in pdfunite (bsc#1102531). - CVE-2018-16646: Fixed infinite recursion in poppler/Parser.cc:Parser::getObj() function (bsc#1107597). - CVE-2018-19058: Fixed reachable abort in Object.h leading to denial of service (bsc#1115187). - CVE-2018-19059: Fixed out-of-bounds read in EmbFile:save2 in FileSpec.cc leading to denial of service (bsc#1115186). - CVE-2018-19060: Fixed NULL pointer dereference in goo/GooString.h leading to denial of service (bsc#1115185). - CVE-2018-19149: Fixed NULL pointer dereference in _poppler_attachment_new when called from poppler_annot_file_attachment_get_attachment (bsc#1115626). - CVE-2017-18267: Fixed denial of service (infinite recursion) via a crafted PDF file (bsc#1092945). - CVE-2018-20650: Fixed issue where a reachable Object in dictLookup assertion allows attackers to cause DOS (bsc#1120939).
References: https://www.suse.com/support/update/announcement/2023/suse-su-20232906-1/, https://bugzilla.suse.com/1092945, https://bugzilla.suse.com/1102531, https://bugzilla.suse.com/1107597, https://bugzilla.suse.com/1114966, https://bugzilla.suse.com/1115185, https://bugzilla.suse.com/1115186, https://bugzilla.suse.com/1115187, https://bugzilla.suse.com/1115626, https://bugzilla.suse.com/1120939, https://bugzilla.suse.com/1124150, https://bugzilla.suse.com/1149635, https://bugzilla.suse.com/1199272, https://www.suse.com/security/cve/CVE-2017-18267, https://www.suse.com/security/cve/CVE-2018-13988, https://www.suse.com/security/cve/CVE-2018-16646, https://www.suse.com/security/cve/CVE-2018-18897, https://www.suse.com/security/cve/CVE-2018-19058, https://www.suse.com/security/cve/CVE-2018-19059, https://www.suse.com/security/cve/CVE-2018-19060, https://www.suse.com/security/cve/CVE-2018-19149, https://www.suse.com/security/cve/CVE-2018-20481, https://www.suse.com/security/cve/CVE-2018-20650, https://www.suse.com/security/cve/CVE-2018-21009, https://www.suse.com/security/cve/CVE-2019-7310, https://www.suse.com/security/cve/CVE-2022-27337
Affected packages
Package
Name: poppler
Purl: pkg:rpm/suse/poppler&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5
Affected ranges
Type: ECOSYSTEM
Events:
