Oval Definition:oval:com.redhat.rhsa:def:20192713
Revision Date:2019-09-12Version:636
Title:RHSA-2019:2713: poppler security update (Moderate)
Description:Poppler is a Portable Document Format (PDF) rendering library, used by applications such as Evince.

Security Fix(es):

  • poppler: heap-based buffer over-read in XRef::getEntry in XRef.cc (CVE-2019-7310)

  • poppler: heap-based buffer overflow in function ImageStream::getLine() in Stream.cc (CVE-2019-9200)

  • poppler: heap-based buffer over-read in function PSOutputDev::checkPageSlice in PSOutputDev.cc (CVE-2019-10871)

  • poppler: heap-based buffer over-read in JPXStream::init in JPEG2000Stream.cc (CVE-2019-12293)

  • poppler: memory leak in GfxColorSpace::setDisplayProfile in GfxState.cc (CVE-2018-18897)

  • poppler: NULL pointer dereference in the XRef::getEntry in XRef.cc (CVE-2018-20481)

  • poppler: reachable Object::getString assertion in AnnotRichMedia class in Annot.c (CVE-2018-20551)

  • poppler: reachable Object::dictLookup assertion in FileSpec class in FileSpec.cc (CVE-2018-20650)

  • poppler: SIGABRT PDFDoc::setup class in PDFDoc.cc (CVE-2018-20662)

  • poppler: heap-based buffer over-read in function downsample_row_box_filter in CairoRescaleBox.cc (CVE-2019-9631)

  • poppler: stack consumption in function Dict::find() in Dict.cc (CVE-2019-9903)

  • poppler: integer overflow in JPXStream::init function leading to memory consumption (CVE-2019-9959)

    For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2018-18897
    CVE-2018-20481
    CVE-2018-20551
    CVE-2018-20650
    CVE-2018-20662
    CVE-2019-10871
    CVE-2019-12293
    CVE-2019-7310
    CVE-2019-9200
    CVE-2019-9631
    CVE-2019-9903
    CVE-2019-9959
    RHSA-2019:2713
    Platform(s):Red Hat Enterprise Linux 8
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 8 is installed
  • OR Red Hat CoreOS 4 is installed
  • AND
  • poppler is earlier than 0:0.66.0-11.el8_0.12
  • AND poppler is signed with Red Hat redhatrelease2 key
  • poppler-cpp is earlier than 0:0.66.0-11.el8_0.12
  • AND poppler-cpp is signed with Red Hat redhatrelease2 key
  • poppler-cpp-devel is earlier than 0:0.66.0-11.el8_0.12
  • AND poppler-cpp-devel is signed with Red Hat redhatrelease2 key
  • poppler-devel is earlier than 0:0.66.0-11.el8_0.12
  • AND poppler-devel is signed with Red Hat redhatrelease2 key
  • poppler-glib is earlier than 0:0.66.0-11.el8_0.12
  • AND poppler-glib is signed with Red Hat redhatrelease2 key
  • poppler-glib-devel is earlier than 0:0.66.0-11.el8_0.12
  • AND poppler-glib-devel is signed with Red Hat redhatrelease2 key
  • poppler-qt5 is earlier than 0:0.66.0-11.el8_0.12
  • AND poppler-qt5 is signed with Red Hat redhatrelease2 key
  • poppler-qt5-devel is earlier than 0:0.66.0-11.el8_0.12
  • AND poppler-qt5-devel is signed with Red Hat redhatrelease2 key
  • poppler-utils is earlier than 0:0.66.0-11.el8_0.12
  • AND poppler-utils is signed with Red Hat redhatrelease2 key
  • BACK