LWN.net Logo

poppler: multiple vulnerabilities

Package(s):poppler CVE #(s):CVE-2013-1788 CVE-2013-1790
Created:March 14, 2013 Updated:April 2, 2013
Description:

From the Red Hat bugzilla:

CVE-2013-1788: A number of invalid memory access flaws were reported in poppler (fixed in version 0.22.1):

  • Fix invalid memory access in 1150.pdf.asan.8.69 [1].
  • Fix invalid memory access in 2030.pdf.asan.69.463 [2].
  • Fix another invalid memory access in 1091.pdf.asan.72.42 [3].
  • Fix invalid memory accesses in 1091.pdf.asan.72.42 [4].
  • Fix invalid memory accesses in 1036.pdf.asan.23.17 [5].

CVE-2013-1790: An uninitialized memory read flaw was reported in poppler (fixed in version 0.22.1):

Initialize refLine totally

Fixes uninitialized memory read in 1004.pdf.asan.7.3

Alerts:
Fedora FEDORA-2013-3457 2013-03-14
Fedora FEDORA-2013-3473 2013-03-14
Mageia MGASA-2013-0095 2013-03-16
Ubuntu USN-1785-1 2013-04-02

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds