rpm package
suse/poppler&distro=SUSE Linux Enterprise Server 12 SP2
pkg:rpm/suse/poppler&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2
Vulnerabilities (11)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2017-14977 | Hig | 7.5 | < 0.24.4-14.13.1 | 0.24.4-14.13.1 | Oct 2, 2017 | The FoFiTrueType::getCFFBlock function in FoFiTrueType.cc in Poppler 0.59.0 has a NULL pointer dereference vulnerability due to lack of validation of a table pointer, which allows an attacker to launch a denial of service attack. | |
| CVE-2017-14520 | Hig | 7.8 | < 0.24.4-14.13.1 | 0.24.4-14.13.1 | Sep 17, 2017 | In Poppler 0.59.0, a floating point exception occurs in Splash::scaleImageYuXd() in Splash.cc, which may lead to a potential attack when handling malicious PDF files. | |
| CVE-2017-14518 | Hig | 7.8 | < 0.24.4-14.13.1 | 0.24.4-14.13.1 | Sep 17, 2017 | In Poppler 0.59.0, a floating point exception exists in the isImageInterpolationRequired() function in Splash.cc via a crafted PDF document. | |
| CVE-2017-14517 | Med | 5.5 | < 0.24.4-14.13.1 | 0.24.4-14.13.1 | Sep 17, 2017 | In Poppler 0.59.0, a NULL Pointer Dereference exists in the XRef::parseEntry() function in XRef.cc via a crafted PDF document. | |
| CVE-2017-9776 | Hig | 7.8 | < 0.24.4-14.6.1 | 0.24.4-14.6.1 | Jun 22, 2017 | Integer overflow leading to Heap buffer overflow in JBIG2Stream.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PDF document. | |
| CVE-2017-9775 | Med | 6.5 | < 0.24.4-14.6.1 | 0.24.4-14.6.1 | Jun 22, 2017 | Stack buffer overflow in GfxState.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of service (application crash) via a crafted PDF document. | |
| CVE-2017-7515 | Med | 5.5 | < 0.43.0-16.5.1 | 0.43.0-16.5.1 | Jun 6, 2017 | poppler through version 0.55.0 is vulnerable to an uncontrolled recursion in pdfunite resulting into potential denial-of-service. | |
| CVE-2017-9408 | Med | 6.5 | < 0.24.4-14.6.1 | 0.24.4-14.6.1 | Jun 2, 2017 | In Poppler 0.54.0, a memory leak vulnerability was found in the function Object::initArray in Object.cc, which allows attackers to cause a denial of service via a crafted file. | |
| CVE-2017-9406 | Med | 6.5 | < 0.24.4-14.3.1 | 0.24.4-14.3.1 | Jun 2, 2017 | In Poppler 0.54.0, a memory leak vulnerability was found in the function gmalloc in gmem.cc, which allows attackers to cause a denial of service via a crafted file. | |
| CVE-2017-7511 | Med | 5.5 | < 0.43.0-16.5.1 | 0.43.0-16.5.1 | May 30, 2017 | poppler since version 0.17.3 has been vulnerable to NULL pointer dereference in pdfunite triggered by specially crafted documents. | |
| CVE-2017-9083 | Med | 6.5 | < 0.24.4-14.3.1 | 0.24.4-14.3.1 | May 19, 2017 | poppler 0.54.0, as used in Evince and other products, has a NULL pointer dereference in the JPXStream::readUByte function in JPXStream.cc. For example, the perf_test utility will crash (segmentation fault) when parsing an invalid PDF file. |
- affected < 0.24.4-14.13.1fixed 0.24.4-14.13.1
The FoFiTrueType::getCFFBlock function in FoFiTrueType.cc in Poppler 0.59.0 has a NULL pointer dereference vulnerability due to lack of validation of a table pointer, which allows an attacker to launch a denial of service attack.
- affected < 0.24.4-14.13.1fixed 0.24.4-14.13.1
In Poppler 0.59.0, a floating point exception occurs in Splash::scaleImageYuXd() in Splash.cc, which may lead to a potential attack when handling malicious PDF files.
- affected < 0.24.4-14.13.1fixed 0.24.4-14.13.1
In Poppler 0.59.0, a floating point exception exists in the isImageInterpolationRequired() function in Splash.cc via a crafted PDF document.
- affected < 0.24.4-14.13.1fixed 0.24.4-14.13.1
In Poppler 0.59.0, a NULL Pointer Dereference exists in the XRef::parseEntry() function in XRef.cc via a crafted PDF document.
- affected < 0.24.4-14.6.1fixed 0.24.4-14.6.1
Integer overflow leading to Heap buffer overflow in JBIG2Stream.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PDF document.
- affected < 0.24.4-14.6.1fixed 0.24.4-14.6.1
Stack buffer overflow in GfxState.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of service (application crash) via a crafted PDF document.
- affected < 0.43.0-16.5.1fixed 0.43.0-16.5.1
poppler through version 0.55.0 is vulnerable to an uncontrolled recursion in pdfunite resulting into potential denial-of-service.
- affected < 0.24.4-14.6.1fixed 0.24.4-14.6.1
In Poppler 0.54.0, a memory leak vulnerability was found in the function Object::initArray in Object.cc, which allows attackers to cause a denial of service via a crafted file.
- affected < 0.24.4-14.3.1fixed 0.24.4-14.3.1
In Poppler 0.54.0, a memory leak vulnerability was found in the function gmalloc in gmem.cc, which allows attackers to cause a denial of service via a crafted file.
- affected < 0.43.0-16.5.1fixed 0.43.0-16.5.1
poppler since version 0.17.3 has been vulnerable to NULL pointer dereference in pdfunite triggered by specially crafted documents.
- affected < 0.24.4-14.3.1fixed 0.24.4-14.3.1
poppler 0.54.0, as used in Evince and other products, has a NULL pointer dereference in the JPXStream::readUByte function in JPXStream.cc. For example, the perf_test utility will crash (segmentation fault) when parsing an invalid PDF file.