Fedora alert FEDORA-2010-15981 (poppler)
| From: | updates@fedoraproject.org | |
| To: | package-announce@lists.fedoraproject.org | |
| Subject: | [SECURITY] Fedora 12 Update: poppler-0.12.4-5.fc12 | |
| Date: | Tue, 19 Oct 2010 07:09:48 +0000 | |
| Message-ID: | <20101019070948.DC2AF110A87@bastion02.phx2.fedoraproject.org> | |
| Archive‑link: | Article |
-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2010-15981 2010-10-08 19:56:46 -------------------------------------------------------------------------------- Name : poppler Product : Fedora 12 Version : 0.12.4 Release : 5.fc12 URL : http://poppler.freedesktop.org/ Summary : PDF rendering library Description : Poppler, a PDF rendering library, is a fork of the xpdf PDF viewer developed by Derek Noonburg of Glyph and Cog, LLC. -------------------------------------------------------------------------------- ChangeLog: * Thu Oct 7 2010 Marek Kasik <mkasik@redhat.com> - 0.12.4-5 - Add poppler-0.12.4-CVE-2010-3702.patch (Properly initialize parser) - Add poppler-0.12.4-CVE-2010-3703.patch (Properly initialize stack) - Add poppler-0.12.4-CVE-2010-3704.patch (Fix crash in broken pdf (code < 0)) - Resolves: #639861 * Mon Jul 19 2010 Marek Kasik <mkasik@redhat.com> - 0.12.4-4 - Accept 4-digit values in ToUnicode CMaps - (#574964) * Tue Jun 29 2010 Marek Kasik <mkasik@redhat.com> - 0.12.4-3 - Fix initialization of members of TextOutputDev in its constructor - (#606870) * Thu Mar 4 2010 Marek Kasik <mkasik@redhat.com> - 0.12.4-2 - Fix showing of radio buttons (#480868) * Fri Feb 19 2010 Marek Kasik <mkasik@redhat.com> - 0.12.4-1 - Update to 0.12.4 * Mon Feb 15 2010 Marek Kasik <mkasik@redhat.com> - 0.12.3-9 - Fix downscaling of rotated pages (#563353) * Thu Jan 28 2010 Marek Kasik <mkasik@redhat.com> - 0.12.3-8 - Get current FcConfig before using it (#533992) * Sun Jan 24 2010 Rex Dieter <rdieter@fedoraproject.org> - 0.12.3-7 - use alternative/upstream downscale patch (#556549, fdo#5589) * Wed Jan 20 2010 Marek Kasik <mkasik@redhat.com> - 0.12.3-6 - Add dependency on poppler-data (#553991) * Tue Jan 19 2010 Rex Dieter <rdieter@fedoraproject.org> - 0.12.3-5 - cairo backend, scale images correctly (#556549, fdo#5589) * Fri Jan 15 2010 Rex Dieter <rdieter@fedoraproject.org> - 0.12.3-4 - Sanitize versioned Obsoletes/Provides * Fri Jan 15 2010 Marek Kasik <mkasik@redhat.com> - 0.12.3-3 - Correct permissions of goo/GooTimer.h - Convert pdftohtml.1 to utf8 - Make the pdftohtml's Provides/Obsoletes versioned * Thu Jan 7 2010 Rex Dieter <rdieter@fedoraproject.org> - 0.12.3-1 - poppler-0.12.3 * Mon Nov 23 2009 Rex Dieter <rdieter@fedoraproject.org> - 0.12.2-1 - poppler-0.12.2 -------------------------------------------------------------------------------- References: [ 1 ] Bug #595245 - CVE-2010-3702 xpdf: uninitialized Gfx::parser pointer dereference https://bugzilla.redhat.com/show_bug.cgi?id=595245 [ 2 ] Bug #638960 - CVE-2010-3704 xpdf: array indexing error in FoFiType1::parse() https://bugzilla.redhat.com/show_bug.cgi?id=638960 [ 3 ] Bug #639356 - CVE-2010-3703 poppler: use of initialized pointer in PostScriptFunction https://bugzilla.redhat.com/show_bug.cgi?id=639356 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update poppler' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-...
