SUSE-SU-2018:1691-1: moderate: Security update for poppler
sle-security-updates at lists.suse.com
sle-security-updates at lists.suse.com
Thu Jun 14 07:17:11 MDT 2018
SUSE Security Update: Security update for poppler
______________________________________________________________________________
Announcement ID: SUSE-SU-2018:1691-1
Rating: moderate
References: #1061265 #1064593 #1074453
Cross-References: CVE-2017-1000456 CVE-2017-14977 CVE-2017-15565
Affected Products:
SUSE Linux Enterprise Software Development Kit 11-SP4
SUSE Linux Enterprise Server 11-SP4
SUSE Linux Enterprise Debuginfo 11-SP4
______________________________________________________________________________
An update that fixes three vulnerabilities is now available.
Description:
This update for poppler fixes the following issues:
- CVE-2017-14977: Fixed a NULL pointer dereference vulnerability in the
FoFiTrueType::getCFFBlock() function in FoFiTrueType.cc that occurred
due to lack of validation of a table pointer, which allows an attacker
to launch a denial of service attack. (bsc#1061265)
- CVE-2017-1000456: Validate boundaries in TextPool::addWord to prevent
overflows in subsequent calculations (bsc#1074453)
- CVE-2017-15565: Prevent NULL Pointer dereference in the
GfxImageColorMap::getGrayLine() function via a crafted PDF document
(bsc#1064593)
Patch Instructions:
To install this SUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- SUSE Linux Enterprise Software Development Kit 11-SP4:
zypper in -t patch sdksp4-poppler-13653=1
- SUSE Linux Enterprise Server 11-SP4:
zypper in -t patch slessp4-poppler-13653=1
- SUSE Linux Enterprise Debuginfo 11-SP4:
zypper in -t patch dbgsp4-poppler-13653=1
Package List:
- SUSE Linux Enterprise Software Development Kit 11-SP4 (i586 ia64 ppc64 s390x x86_64):
libpoppler-devel-0.12.3-1.13.3.2
libpoppler-glib-devel-0.12.3-1.13.3.2
libpoppler-qt2-0.12.3-1.13.3.2
libpoppler-qt3-devel-0.12.3-1.13.3.2
libpoppler-qt4-devel-0.12.3-1.13.3.2
- SUSE Linux Enterprise Software Development Kit 11-SP4 (i586 x86_64):
poppler-tools-0.12.3-1.13.3.2
- SUSE Linux Enterprise Server 11-SP4 (i586 ia64 ppc64 s390x x86_64):
libpoppler-glib4-0.12.3-1.13.3.2
libpoppler-qt4-3-0.12.3-1.13.3.2
libpoppler5-0.12.3-1.13.3.2
poppler-tools-0.12.3-1.13.3.2
- SUSE Linux Enterprise Debuginfo 11-SP4 (i586 ia64 ppc64 s390x x86_64):
poppler-debuginfo-0.12.3-1.13.3.2
poppler-debugsource-0.12.3-1.13.3.2
References:
https://www.suse.com/security/cve/CVE-2017-1000456.html
https://www.suse.com/security/cve/CVE-2017-14977.html
https://www.suse.com/security/cve/CVE-2017-15565.html
https://bugzilla.suse.com/1061265
https://bugzilla.suse.com/1064593
https://bugzilla.suse.com/1074453
More information about the sle-security-updates
mailing list