shield
Security update for podofo
SUSE-SLE-SDK-12-SP3-2018-1744
This update for podofo fixes the following issues: - CVE-2017-5852: The PoDoFo::PdfPage::GetInheritedKeyFromObject function allowed remote attackers to cause a denial of service (infinite loop) via a crafted file (bsc#1023067). - CVE-2017-5853: Integer overflow allowed remote attackers to have unspecified impact via a crafted file (bsc#1023069). - CVE-2017-5854: Prevent NULL pointer dereference that allowed remote attackers to cause a denial of service via a crafted file (bsc#1023070). - CVE-2017-5855: The PoDoFo::PdfParser::ReadXRefSubsection function allowed remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file (bsc#1023071). - CVE-2017-5886: Prevent heap-based buffer overflow in the PoDoFo::PdfTokenizer::GetNextToken function that allowed remote attackers to have unspecified impact via a crafted file (bsc#1023380). - CVE-2017-6847: The PoDoFo::PdfVariant::DelayedLoad function allowed remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file (bsc#1027778). - CVE-2017-6844: Buffer overflow in the PoDoFo::PdfParser::ReadXRefSubsection function allowed remote attackers to have unspecified impact via a crafted file (bsc#1027782). - CVE-2017-6840: The ColorChanger::GetColorFromStack function allowed remote attackers to cause a denial of service (invalid read) via a crafted file (bsc#1027787). - CVE-2017-7378: The PoDoFo::PdfPainter::ExpandTabs function allowed remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted PDF document (bsc#1032017). - CVE-2017-7379: The PoDoFo::PdfSimpleEncoding::ConvertToEncoding function allowed remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted PDF document (bsc#1032018). - CVE-2017-7380: Prevent NULL pointer dereference that allowed remote attackers to cause a denial of service via a crafted PDF document (bsc#1032019). - CVE-2017-7994: The function TextExtractor::ExtractText allowed remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PDF document (bsc#1035534). - CVE-2017-8054: The function PdfPagesTree::GetPageNodeFromArray allowed remote attackers to cause a denial of service (infinite recursion and application crash) via a crafted PDF document (bsc#1035596). - CVE-2017-8787: The PoDoFo::PdfXRefStreamParserObject::ReadXRefStreamEntry function allowed remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted PDF file (bsc#1037739). - CVE-2018-5308: Properly validate memcpy arguments in the PdfMemoryOutputStream::Write function to prevent remote attackers from causing a denial-of-service or possibly have unspecified other impact via a crafted pdf file (bsc#1075772). - CVE-2018-8001: Prevent heap-based buffer over-read vulnerability in UnescapeName() that allowed remote attackers to cause a denial-of-service or possibly unspecified other impact via a crafted pdf file (bsc#1084894).
-
Release DateAug 22 2018
-
ReferencesBugzilla: 1023067, 1023069, 1023070, 1023071, 1023380, 1027778, 1027782, 1027787, 1032017, 1032018, 1032019, 1035534, 1035596, 1037739, 1075772, 1084894
CVEs: CVE-2017-5852, CVE-2017-5853, CVE-2017-5854, CVE-2017-5855, CVE-2017-5886, CVE-2017-6840, CVE-2017-6844, CVE-2017-6847, CVE-2017-7378, CVE-2017-7379, CVE-2017-7380, CVE-2017-7994, CVE-2017-8054, CVE-2017-8787, CVE-2018-5308, CVE-2018-8001 -
Typesecurity
-
Severitymoderate
cloud_download Downloads
SUSE Linux Enterprise Software Development Kit 12.3 aarch64
-
Packageslibpodofo-devel
Development files for podofopodofo0.9.2-3.3.1lock rpm
Tools to work with PDF files0.9.2-3.3.1lock src
SUSE Linux Enterprise Software Development Kit 12.3 ppc64le
-
Packageslibpodofo-devel
Development files for podofopodofo0.9.2-3.3.1lock rpm
Tools to work with PDF files0.9.2-3.3.1lock src
SUSE Linux Enterprise Software Development Kit 12.3 s390x
-
Packageslibpodofo-devel
Development files for podofopodofo0.9.2-3.3.1lock rpm
Tools to work with PDF files0.9.2-3.3.1lock src
SUSE Linux Enterprise Software Development Kit 12.3 x86_64
-
Packageslibpodofo-devel
Development files for podofopodofo0.9.2-3.3.1lock rpm
Tools to work with PDF files0.9.2-3.3.1lock src