SUSE alert SUSE-SU-2023:2907-1 (poppler)
| From: | sle-security-updates@lists.suse.com | |
| To: | sle-security-updates@lists.suse.com | |
| Subject: | SUSE-SU-2023:2907-1: moderate: Security update for poppler | |
| Date: | Thu, 20 Jul 2023 12:30:45 -0000 | |
| Message-ID: | <168985624542.12688.14490509713488733035@smelt2.suse.de> |
# Security update for poppler Announcement ID: SUSE-SU-2023:2907-1 Rating: moderate References: * #1092945 * #1102531 * #1107597 * #1114966 * #1115185 * #1115186 * #1115187 * #1115626 * #1120939 * #1124150 * #1136105 * #1149635 * #1199272 Cross-References: * CVE-2017-18267 * CVE-2018-13988 * CVE-2018-16646 * CVE-2018-18897 * CVE-2018-19058 * CVE-2018-19059 * CVE-2018-19060 * CVE-2018-19149 * CVE-2018-20481 * CVE-2018-20650 * CVE-2018-21009 * CVE-2019-12293 * CVE-2019-7310 * CVE-2022-27337 CVSS scores: * CVE-2017-18267 ( SUSE ): 3.3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2017-18267 ( NVD ): 5.5 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2018-13988 ( SUSE ): 5.3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2018-13988 ( NVD ): 6.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2018-16646 ( SUSE ): 3.3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2018-16646 ( NVD ): 6.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2018-18897 ( SUSE ): 3.3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2018-18897 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2018-18897 ( NVD ): 6.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2018-19058 ( SUSE ): 3.3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2018-19058 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2018-19058 ( NVD ): 6.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2018-19059 ( SUSE ): 3.3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2018-19059 ( NVD ): 6.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2018-19060 ( SUSE ): 3.3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2018-19060 ( NVD ): 6.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2018-19149 ( SUSE ): 3.3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2018-19149 ( NVD ): 6.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2018-20481 ( SUSE ): 3.3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2018-20481 ( NVD ): 6.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2018-20650 ( SUSE ): 3.3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2018-20650 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2018-20650 ( NVD ): 6.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2018-21009 ( SUSE ): 4.0 CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2018-21009 ( NVD ): 8.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2019-12293 ( SUSE ): 5.1 CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2019-12293 ( NVD ): 8.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2019-7310 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2019-7310 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2019-7310 ( NVD ): 8.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2022-27337 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2022-27337 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 * SUSE Linux Enterprise Software Development Kit 12 SP5 An update that solves 14 vulnerabilities can now be installed. ## Description: This update for poppler fixes the following issues: * CVE-2022-27337: Fixed a logic error in the Hints::Hints function which can cause denial of service (bsc#1199272). * CVE-2018-21009: Fixed integer overflow in Parser:makeStream in Parser.cc (bsc#1149635). * CVE-2019-12293: Fixed heap-based buffer over-read in JPXStream:init in JPEG2000Stream.cc (bsc#1136105). * CVE-2018-20481: Fixed memory leak in GfxColorSpace:setDisplayProfile in GfxState.cc (bsc#1114966). * CVE-2019-7310: Fixed a heap-based buffer over-read allows remote attackers to cause DOS via a special crafted PDF (bsc#1124150). * CVE-2018-13988: Fixed buffer overflow in pdfunite (bsc#1102531). * CVE-2018-16646: Fixed infinite recursion in poppler/Parser.cc:Parser::getObj() function (bsc#1107597). * CVE-2018-19058: Fixed reachable abort in Object.h leading to denial of service (bsc#1115187). * CVE-2018-19059: Fixed out-of-bounds read in EmbFile:save2 in FileSpec.cc leading to denial of service (bsc#1115186). * CVE-2018-19060: Fixed NULL pointer dereference in goo/GooString.h leading to denial of service (bsc#1115185). * CVE-2018-19149: Fixed NULL pointer dereference in _poppler_attachment_new when called from poppler_annot_file_attachment_get_attachment (bsc#1115626). * CVE-2017-18267: Fixed denial of service (infinite recursion) via a crafted PDF file (bsc#1092945). * CVE-2018-20650: Fixed issue where a reachable Object in dictLookup assertion allows attackers to cause DOS (bsc#1120939). ## Patch Instructions: To install this SUSE Moderate update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Software Development Kit 12 SP5 zypper in -t patch SUSE-SLE-SDK-12-SP5-2023-2907=1 * SUSE Linux Enterprise High Performance Computing 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2023-2907=1 * SUSE Linux Enterprise Server 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2023-2907=1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 zypper in -t patch SUSE-SLE-SERVER-12-SP5-2023-2907=1 ## Package List: * SUSE Linux Enterprise Software Development Kit 12 SP5 (aarch64 ppc64le s390x x86_64) * libpoppler-qt4-devel-0.43.0-16.25.1 * typelib-1_0-Poppler-0_18-0.43.0-16.25.1 * libpoppler-glib-devel-0.43.0-16.25.1 * libpoppler-devel-0.43.0-16.25.1 * poppler-debugsource-0.43.0-16.25.1 * libpoppler-cpp0-0.43.0-16.25.1 * SUSE Linux Enterprise Software Development Kit 12 SP5 (ppc64le s390x x86_64) * libpoppler-cpp0-debuginfo-0.43.0-16.25.1 * SUSE Linux Enterprise High Performance Computing 12 SP5 (aarch64 x86_64) * poppler-tools-0.43.0-16.25.1 * libpoppler-glib8-0.43.0-16.25.1 * libpoppler-glib8-debuginfo-0.43.0-16.25.1 * libpoppler60-0.43.0-16.25.1 * poppler-tools-debuginfo-0.43.0-16.25.1 * libpoppler-qt4-4-0.43.0-16.25.1 * libpoppler60-debuginfo-0.43.0-16.25.1 * poppler-debugsource-0.43.0-16.25.1 * SUSE Linux Enterprise High Performance Computing 12 SP5 (x86_64) * libpoppler-qt4-4-debuginfo-0.43.0-16.25.1 * SUSE Linux Enterprise Server 12 SP5 (aarch64 ppc64le s390x x86_64) * poppler-tools-0.43.0-16.25.1 * libpoppler-glib8-0.43.0-16.25.1 * libpoppler-glib8-debuginfo-0.43.0-16.25.1 * libpoppler60-0.43.0-16.25.1 * poppler-tools-debuginfo-0.43.0-16.25.1 * libpoppler-qt4-4-0.43.0-16.25.1 * libpoppler60-debuginfo-0.43.0-16.25.1 * poppler-debugsource-0.43.0-16.25.1 * SUSE Linux Enterprise Server 12 SP5 (ppc64le s390x x86_64) * libpoppler-qt4-4-debuginfo-0.43.0-16.25.1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (ppc64le x86_64) * poppler-tools-0.43.0-16.25.1 * libpoppler-qt4-4-debuginfo-0.43.0-16.25.1 * libpoppler-glib8-0.43.0-16.25.1 * libpoppler-glib8-debuginfo-0.43.0-16.25.1 * libpoppler60-0.43.0-16.25.1 * poppler-tools-debuginfo-0.43.0-16.25.1 * libpoppler-qt4-4-0.43.0-16.25.1 * libpoppler60-debuginfo-0.43.0-16.25.1 * poppler-debugsource-0.43.0-16.25.1 ## References: * https://www.suse.com/security/cve/CVE-2017-18267.html * https://www.suse.com/security/cve/CVE-2018-13988.html * https://www.suse.com/security/cve/CVE-2018-16646.html * https://www.suse.com/security/cve/CVE-2018-18897.html * https://www.suse.com/security/cve/CVE-2018-19058.html * https://www.suse.com/security/cve/CVE-2018-19059.html * https://www.suse.com/security/cve/CVE-2018-19060.html * https://www.suse.com/security/cve/CVE-2018-19149.html * https://www.suse.com/security/cve/CVE-2018-20481.html * https://www.suse.com/security/cve/CVE-2018-20650.html * https://www.suse.com/security/cve/CVE-2018-21009.html * https://www.suse.com/security/cve/CVE-2019-12293.html * https://www.suse.com/security/cve/CVE-2019-7310.html * https://www.suse.com/security/cve/CVE-2022-27337.html * https://bugzilla.suse.com/show_bug.cgi?id=1092945 * https://bugzilla.suse.com/show_bug.cgi?id=1102531 * https://bugzilla.suse.com/show_bug.cgi?id=1107597 * https://bugzilla.suse.com/show_bug.cgi?id=1114966 * https://bugzilla.suse.com/show_bug.cgi?id=1115185 * https://bugzilla.suse.com/show_bug.cgi?id=1115186 * https://bugzilla.suse.com/show_bug.cgi?id=1115187 * https://bugzilla.suse.com/show_bug.cgi?id=1115626 * https://bugzilla.suse.com/show_bug.cgi?id=1120939 * https://bugzilla.suse.com/show_bug.cgi?id=1124150 * https://bugzilla.suse.com/show_bug.cgi?id=1136105 * https://bugzilla.suse.com/show_bug.cgi?id=1149635 * https://bugzilla.suse.com/show_bug.cgi?id=1199272
