[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SU-2023:4362-1 -- SLES poppler, libpoppler-glib8, libpoppler-qt4-4, libpoppler60

ID: oval:org.secpod.oval:def:89051056Date: (C)2023-11-28   (M)2024-01-03
Class: PATCHFamily: unix




This update for poppler fixes the following issues: * CVE-2019-9545: Fixed a potential crash due to uncontrolled recursion in the JBIG parser . * CVE-2019-9631: Fixed an out of bounds read when converting a PDF to an image . * CVE-2022-37052: Fixed a reachable assertion when extracting pages of a PDf file . * CVE-2020-36023: Fixed a stack bugger overflow in FoFiType1C:cvtGlyph . * CVE-2019-13287: Fixed an out-of-bounds read vulnerability in the function SplashXPath:strokeAdjust . * CVE-2018-18456: Fixed a stack-based buffer over-read via a crafted pdf file . * CVE-2018-18454: Fixed heap-based buffer over-read via a crafted pdf file . * CVE-2019-14292: Fixed an out of bounds read in GfxState.cc . * CVE-2022-48545: Fixed an infinite recursion in Catalog::findDestInTree which can cause denial of service .

Platform:
SUSE Linux Enterprise Server 12 SP5
Product:
poppler
libpoppler-glib8
libpoppler-qt4-4
libpoppler60
Reference:
SUSE-SU-2023:4362-1
CVE-2018-18454
CVE-2018-18456
CVE-2019-13287
CVE-2019-14292
CVE-2019-9545
CVE-2019-9631
CVE-2020-36023
CVE-2022-37052
CVE-2022-48545
CVE    9
CVE-2022-48545
CVE-2019-14292
CVE-2019-9631
CVE-2022-37052
...
CPE    2
cpe:/a:freedesktop:poppler
cpe:/o:suse:suse_linux_enterprise_server:12:sp5

© SecPod Technologies