[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CESA-2020:1074 -- centos 7 evince

ID: oval:org.secpod.oval:def:205483Date: (C)2020-04-10   (M)2023-12-20
Class: PATCHFamily: unix




Poppler is a Portable Document Format rendering library, used by applications such as Evince. The evince packages provide a simple multi-page document viewer for Portable Document Format , PostScript , Encapsulated PostScript files, and, with additional back-ends, also the Device Independent File format files. Security Fix: * poppler: integer overflow in Parser::makeStream in Parser.cc * poppler: heap-based buffer over-read in function PSOutputDev::checkPageSlice in PSOutputDev.cc * poppler: heap-based buffer over-read in JPXStream::init in JPEG2000Stream.cc * poppler: integer overflow in JPXStream::init function leading to memory consumption * evince: uninitialized memory use in function tiff_document_render and tiff_document_get_thumbnail For more details about the security issue, including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.8 Release Notes linked from the References section.

Platform:
CentOS 7
Product:
evince
Reference:
CESA-2020:1074
CVE-2018-21009
CVE-2019-9959
CVE-2019-10871
CVE-2019-11459
CVE-2019-12293
CVE    5
CVE-2018-21009
CVE-2019-10871
CVE-2019-12293
CVE-2019-9959
...
CPE    2
cpe:/a:gnome:evince
cpe:/o:centos:centos:7

© SecPod Technologies