[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CESA-2018:3140 -- centos 7 clutter-gst3

ID: oval:org.secpod.oval:def:205078Date: (C)2021-01-19   (M)2023-11-18
Class: PATCHFamily: unix




GNOME is the default desktop environment of Red Hat Enterprise Linux. Security Fix: * libsoup: Crash in soup_cookie_jar.c:get_cookies on empty hostnames * poppler: Infinite recursion in fofi/FoFiType1C.cc:FoFiType1C::cvtGlyph function allows denial of service * libgxps: heap based buffer over read in ft_font_face_hash function of gxps-fonts.c * libgxps: Stack-based buffer overflow in calling glib in gxps_images_guess_content_type of gcontenttype.c * poppler: NULL pointer dereference in Annot.h:AnnotPath::getCoordsLength allows for denial of service via crafted PDF * poppler: out of bounds read in pdfunite For more details about the security issue, including the impact, a CVSS score, and other related information, refer to the CVE page listed in the References section. Red Hat would like to thank chenyuan for reporting CVE-2018-10733 and CVE-2018-10767 and Hosein Askari for reporting CVE-2018-13988. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.6 Release Notes linked from the References section.

Platform:
CentOS 7
Product:
clutter-gst3
Reference:
CESA-2018:3140
CVE-2018-13988
CVE-2018-12910
CVE-2018-10768
CVE-2018-10767
CVE-2018-10733
CVE-2017-18267
CVE-2017-2862
CVE-2015-9382
CVE-2015-9381
CVE-2018-14036
CVE-2018-4200
CVE-2018-11712
CVE-2018-11713
CVE-2018-4121
CVE-2018-4204
CVE    15
CVE-2017-18267
CVE-2017-2862
CVE-2018-10733
CVE-2018-11713
...

© SecPod Technologies