Oval Definition:oval:com.redhat.rhsa:def:20192022
Revision Date:2019-08-06Version:636
Title:RHSA-2019:2022: poppler security, bug fix, and enhancement update (Moderate)
Description:Poppler is a Portable Document Format (PDF) rendering library, used by applications such as Evince or Okular.

Security Fix(es):

  • poppler: heap-based buffer over-read in XRef::getEntry in XRef.cc (CVE-2019-7310)

  • poppler: heap-based buffer overflow in function ImageStream::getLine() in Stream.cc (CVE-2019-9200)

  • poppler: infinite recursion in Parser::getObj function in Parser.cc (CVE-2018-16646)

  • poppler: memory leak in GfxColorSpace::setDisplayProfile in GfxState.cc (CVE-2018-18897)

  • poppler: reachable abort in Object.h (CVE-2018-19058)

  • poppler: out-of-bounds read in EmbFile::save2 in FileSpec.cc (CVE-2018-19059)

  • poppler: pdfdetach utility does not validate save paths (CVE-2018-19060)

  • poppler: NULL pointer dereference in _poppler_attachment_new (CVE-2018-19149)

  • poppler: NULL pointer dereference in the XRef::getEntry in XRef.cc (CVE-2018-20481)

  • poppler: reachable Object::dictLookup assertion in FileSpec class in FileSpec.cc (CVE-2018-20650)

  • poppler: SIGABRT PDFDoc::setup class in PDFDoc.cc (CVE-2018-20662)

  • poppler: heap-based buffer over-read in function downsample_row_box_filter in CairoRescaleBox.cc (CVE-2019-9631)

    For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

    Additional Changes:

    For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.7 Release Notes linked from the References section.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2018-16646
    CVE-2018-18897
    CVE-2018-19058
    CVE-2018-19059
    CVE-2018-19060
    CVE-2018-19149
    CVE-2018-20481
    CVE-2018-20650
    CVE-2018-20662
    CVE-2019-7310
    CVE-2019-9200
    CVE-2019-9631
    RHSA-2019:2022
    Platform(s):Red Hat Enterprise Linux 7
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 7 is installed
  • AND
  • poppler is earlier than 0:0.26.5-38.el7
  • AND poppler is signed with Red Hat redhatrelease2 key
  • poppler-cpp is earlier than 0:0.26.5-38.el7
  • AND poppler-cpp is signed with Red Hat redhatrelease2 key
  • poppler-cpp-devel is earlier than 0:0.26.5-38.el7
  • AND poppler-cpp-devel is signed with Red Hat redhatrelease2 key
  • poppler-demos is earlier than 0:0.26.5-38.el7
  • AND poppler-demos is signed with Red Hat redhatrelease2 key
  • poppler-devel is earlier than 0:0.26.5-38.el7
  • AND poppler-devel is signed with Red Hat redhatrelease2 key
  • poppler-glib is earlier than 0:0.26.5-38.el7
  • AND poppler-glib is signed with Red Hat redhatrelease2 key
  • poppler-glib-devel is earlier than 0:0.26.5-38.el7
  • AND poppler-glib-devel is signed with Red Hat redhatrelease2 key
  • poppler-qt is earlier than 0:0.26.5-38.el7
  • AND poppler-qt is signed with Red Hat redhatrelease2 key
  • poppler-qt-devel is earlier than 0:0.26.5-38.el7
  • AND poppler-qt-devel is signed with Red Hat redhatrelease2 key
  • poppler-utils is earlier than 0:0.26.5-38.el7
  • AND poppler-utils is signed with Red Hat redhatrelease2 key
  • okular is earlier than 0:4.10.5-7.el7
  • AND okular is signed with Red Hat redhatrelease2 key
  • okular-devel is earlier than 0:4.10.5-7.el7
  • AND okular-devel is signed with Red Hat redhatrelease2 key
  • okular-libs is earlier than 0:4.10.5-7.el7
  • AND okular-libs is signed with Red Hat redhatrelease2 key
  • okular-part is earlier than 0:4.10.5-7.el7
  • AND okular-part is signed with Red Hat redhatrelease2 key
  • evince is earlier than 0:3.28.2-8.el7
  • AND evince is signed with Red Hat redhatrelease2 key
  • evince-browser-plugin is earlier than 0:3.28.2-8.el7
  • AND evince-browser-plugin is signed with Red Hat redhatrelease2 key
  • evince-devel is earlier than 0:3.28.2-8.el7
  • AND evince-devel is signed with Red Hat redhatrelease2 key
  • evince-dvi is earlier than 0:3.28.2-8.el7
  • AND evince-dvi is signed with Red Hat redhatrelease2 key
  • evince-libs is earlier than 0:3.28.2-8.el7
  • AND evince-libs is signed with Red Hat redhatrelease2 key
  • evince-nautilus is earlier than 0:3.28.2-8.el7
  • AND evince-nautilus is signed with Red Hat redhatrelease2 key
  • BACK