SUSE-SU-2023:4546-1
Dashboard / Vulnerabilities / SUSE-SU-2023:4546-1
SUSE-SU-2023:4546-1
Summary: Security update for poppler
Details: This update for poppler fixes the following issues: - CVE-2019-9545: Fixed a potential crash due to uncontrolled recursion in the JBIG parser (bsc#1128114). - CVE-2019-9631: Fixed an out of bounds read when converting a PDF to an image (bsc#1129202). - CVE-2022-37052: Fixed a reachable assertion when extracting pages of a PDf file (bsc#1214726). - CVE-2020-36023: Fixed a stack bugger overflow in FoFiType1C:cvtGlyph (bsc#1214256). - CVE-2019-14292: Fixed an out of bounds read in GfxState.cc (bsc#1143570). - CVE-2022-48545: Fixed an infinite recursion in Catalog::findDestInTree which can cause denial of service (bsc#1214723).
References: https://www.suse.com/support/update/announcement/2023/suse-su-20234546-1/, https://bugzilla.suse.com/1128114, https://bugzilla.suse.com/1129202, https://bugzilla.suse.com/1143570, https://bugzilla.suse.com/1214256, https://bugzilla.suse.com/1214723, https://bugzilla.suse.com/1214726, https://www.suse.com/security/cve/CVE-2019-14292, https://www.suse.com/security/cve/CVE-2019-9545, https://www.suse.com/security/cve/CVE-2019-9631, https://www.suse.com/security/cve/CVE-2020-36023, https://www.suse.com/security/cve/CVE-2022-37052, https://www.suse.com/security/cve/CVE-2022-48545
Affected packages
Package
Name: poppler
Purl: pkg:rpm/suse/poppler&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5
Affected ranges
Type: ECOSYSTEM
Events:
