Advisories ยป MGASA-2019-0276

Updated poppler packages fix security vulnerabilities

Publication date: 15 Sep 2019
Modification date: 15 Sep 2019
Type: security
Affected Mageia releases : 6 , 7
CVE: CVE-2019-9959 , CVE-2019-10871

Description

The updated packages fix security vulnerabilities:

The JPXStream::init function in Poppler 0.78.0 and earlier doesn't check
for negative values of stream length, leading to an Integer Overflow,
thereby making it possible to allocate a large memory chunk on the heap,
with a size controlled by an attacker, as demonstrated by pdftocairo.
(CVE-2019-9959)

An issue was discovered in Poppler 0.74.0. There is a heap-based buffer
over-read in the function PSOutputDev::checkPageSlice at PSOutputDev.cc.
(CVE-2019-10871)
                

References

SRPMS

6/core

7/core