[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CESA-2019:2022 -- centos 7 evince

ID: oval:org.secpod.oval:def:205288Date: (C)2019-09-17   (M)2023-12-20
Class: PATCHFamily: unix




Poppler is a Portable Document Format rendering library, used by applications such as Evince or Okular. Security Fix: * poppler: heap-based buffer over-read in XRef::getEntry in XRef.cc * poppler: heap-based buffer overflow in function ImageStream::getLine in Stream.cc * poppler: infinite recursion in Parser::getObj function in Parser.cc * poppler: memory leak in GfxColorSpace::setDisplayProfile in GfxState.cc * poppler: reachable abort in Object.h * poppler: out-of-bounds read in EmbFile::save2 in FileSpec.cc * poppler: pdfdetach utility does not validate save paths * poppler: NULL pointer dereference in _poppler_attachment_new * poppler: NULL pointer dereference in the XRef::getEntry in XRef.cc * poppler: reachable Object::dictLookup assertion in FileSpec class in FileSpec.cc * poppler: SIGABRT PDFDoc::setup class in PDFDoc.cc * poppler: heap-based buffer over-read in function downsample_row_box_filter in CairoRescaleBox.cc For more details about the security issue, including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section. Additional Changes: For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.7 Release Notes linked from the References section.

Platform:
CentOS 7
Product:
evince
Reference:
CESA-2019:2022
CVE-2018-16646
CVE-2018-18897
CVE-2018-19058
CVE-2018-19059
CVE-2018-19060
CVE-2018-19149
CVE-2018-20481
CVE-2018-20650
CVE-2018-20662
CVE-2019-7310
CVE-2019-9200
CVE-2019-9631
CVE    12
CVE-2018-16646
CVE-2018-19059
CVE-2018-19058
CVE-2018-19060
...
CPE    2
cpe:/o:centos:centos:7
cpe:/a:gnome:evince

© SecPod Technologies