Advisories ยป MGASA-2019-0355

Updated evince packages fix security vulnerability

Publication date: 06 Dec 2019
Modification date: 06 Dec 2019
Type: security
Affected Mageia releases : 7
CVE: CVE-2019-11459

Description

The updated packages fix a security vulnerability:

The tiff_document_render() and tiff_document_get_thumbnail() functions
in the TIFF document backend in GNOME Evince through 3.32.0 did not handle
errors from TIFFReadRGBAImageOriented(), leading to uninitialized memory
use when processing certain TIFF image files. (CVE-2019-11459)
                

References

SRPMS

7/core