CESA-2018:3140 -- centos 7 xdg-desktop-portalID: oval:org.secpod.oval:def:204907 | Date: (C)2021-01-19 (M)2023-11-18 |
Class: PATCH | Family: unix |
GNOME is the default desktop environment of Red Hat Enterprise Linux. Security Fix: * libsoup: Crash in soup_cookie_jar.c:get_cookies on empty hostnames * poppler: Infinite recursion in fofi/FoFiType1C.cc:FoFiType1C::cvtGlyph function allows denial of service * libgxps: heap based buffer over read in ft_font_face_hash function of gxps-fonts.c * libgxps: Stack-based buffer overflow in calling glib in gxps_images_guess_content_type of gcontenttype.c * poppler: NULL pointer dereference in Annot.h:AnnotPath::getCoordsLength allows for denial of service via crafted PDF * poppler: out of bounds read in pdfunite For more details about the security issue, including the impact, a CVSS score, and other related information, refer to the CVE page listed in the References section. Red Hat would like to thank chenyuan for reporting CVE-2018-10733 and CVE-2018-10767 and Hosein Askari for reporting CVE-2018-13988. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.6 Release Notes linked from the References section.
Product: |
xdg-desktop-portal |