|
|
Subscribe / Log in / New account

Mageia alert MGASA-2017-0237 (qpdf)

From:  Mageia Updates <buildsystem-daemon@mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2017-0237: Updated qpdf packages fix security vulnerabilities
Date:  Thu, 3 Aug 2017 21:06:22 +0200
Message-ID:  <20170803190622.E0F549F875@duvel.mageia.org>

MGASA-2017-0237 - Updated qpdf packages fix security vulnerabilities Publication date: 03 Aug 2017 URL: http://advisories.mageia.org/MGASA-2017-0237.html Type: security Affected Mageia releases: 5, 6 CVE: CVE-2017-9208, CVE-2017-9209, CVE-2017-9210, CVE-2017-11624, CVE-2017-11625, CVE-2017-11626, CVE-2017-11627 Description: This snapshot of the upstream development branch (6.0) of qpdf fixes several infinite loop vulnerabilities: CVE-2017-9208, CVE-2017-9209, CVE-2017-9210, CVE-2017-11624, CVE-2017-11625, CVE-2017-11626, CVE-2017-11627. For Mageia 5, the cups-filters package was also rebuilt against this new major version of qpdf. References: - https://bugs.mageia.org/show_bug.cgi?id=20915 - https://github.com/qpdf/qpdf/tree/8ee83ca722baad9434119bb... - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9208 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9209 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-9210 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11624 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11625 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11626 - http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-11627 SRPMS: - 6/core/qpdf-6.0.0-2.20170730.1.mga6 - 5/core/cups-filters-1.0.71-1.3.mga5 - 5/core/qpdf-6.0.0-2.20170730.1.mga5


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds