[ Marc Deslauriers ]
* SECURITY UPDATE: infinite recursion via crafted file
- debian/patches/CVE-2018-16646.patch: avoid cycles in PDF parsing in
poppler/Parser.cc, poppler/XRef.h.
- CVE-2018-16646
* SECURITY UPDATE: denial of service via reachable abort
- debian/patches/CVE-2018-19058.patch: check for stream before calling
stream methods when saving an embedded file in poppler/FileSpec.cc.
- CVE-2018-19058
* SECURITY UPDATE: denial of service via out-of-bounds read
- debian/patches/CVE-2018-19059.patch: check for valid embedded file
before trying to save it in utils/pdfdetach.cc.
- CVE-2018-19059
* SECURITY UPDATE: denial of service via NULL pointer dereference
- debian/patches/CVE-2018-19060.patch: check for valid file name of
embedded file in utils/pdfdetach.cc.
- CVE-2018-19060
-- <email address hidden> (Leonidas S. Barbosa) Fri, 30 Nov 2018 14:36:01 -0300
This bug was fixed in the package poppler - 0.62.0-2ubuntu2.4
---------------
poppler (0.62.0-2ubuntu2.4) bionic-security; urgency=medium
[ Marc Deslauriers ] patches/ CVE-2018- 16646.patch: avoid cycles in PDF parsing in Parser. cc, poppler/XRef.h. patches/ CVE-2018- 19058.patch: check for stream before calling FileSpec. cc. patches/ CVE-2018- 19059.patch: check for valid embedded file patches/ CVE-2018- 19060.patch: check for valid file name of
* SECURITY UPDATE: infinite recursion via crafted file
- debian/
poppler/
- CVE-2018-16646
* SECURITY UPDATE: denial of service via reachable abort
- debian/
stream methods when saving an embedded file in poppler/
- CVE-2018-19058
* SECURITY UPDATE: denial of service via out-of-bounds read
- debian/
before trying to save it in utils/pdfdetach.cc.
- CVE-2018-19059
* SECURITY UPDATE: denial of service via NULL pointer dereference
- debian/
embedded file in utils/pdfdetach.cc.
- CVE-2018-19060
-- <email address hidden> (Leonidas S. Barbosa) Fri, 30 Nov 2018 14:36:01 -0300