VYPR

rpm package

suse/poppler&distro=SUSE Linux Enterprise Server for Raspberry Pi 12 SP2

pkg:rpm/suse/poppler&distro=SUSE%20Linux%20Enterprise%20Server%20for%20Raspberry%20Pi%2012%20SP2

Vulnerabilities (11)

  • CVE-2017-14977HigOct 2, 2017
    affected < 0.24.4-14.13.1fixed 0.24.4-14.13.1

    The FoFiTrueType::getCFFBlock function in FoFiTrueType.cc in Poppler 0.59.0 has a NULL pointer dereference vulnerability due to lack of validation of a table pointer, which allows an attacker to launch a denial of service attack.

  • CVE-2017-14520HigSep 17, 2017
    affected < 0.24.4-14.13.1fixed 0.24.4-14.13.1

    In Poppler 0.59.0, a floating point exception occurs in Splash::scaleImageYuXd() in Splash.cc, which may lead to a potential attack when handling malicious PDF files.

  • CVE-2017-14518HigSep 17, 2017
    affected < 0.24.4-14.13.1fixed 0.24.4-14.13.1

    In Poppler 0.59.0, a floating point exception exists in the isImageInterpolationRequired() function in Splash.cc via a crafted PDF document.

  • CVE-2017-14517MedSep 17, 2017
    affected < 0.24.4-14.13.1fixed 0.24.4-14.13.1

    In Poppler 0.59.0, a NULL Pointer Dereference exists in the XRef::parseEntry() function in XRef.cc via a crafted PDF document.

  • CVE-2017-9776HigJun 22, 2017
    affected < 0.24.4-14.6.1fixed 0.24.4-14.6.1

    Integer overflow leading to Heap buffer overflow in JBIG2Stream.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PDF document.

  • CVE-2017-9775MedJun 22, 2017
    affected < 0.24.4-14.6.1fixed 0.24.4-14.6.1

    Stack buffer overflow in GfxState.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of service (application crash) via a crafted PDF document.

  • CVE-2017-7515MedJun 6, 2017
    affected < 0.43.0-16.5.1fixed 0.43.0-16.5.1

    poppler through version 0.55.0 is vulnerable to an uncontrolled recursion in pdfunite resulting into potential denial-of-service.

  • CVE-2017-9408MedJun 2, 2017
    affected < 0.24.4-14.6.1fixed 0.24.4-14.6.1

    In Poppler 0.54.0, a memory leak vulnerability was found in the function Object::initArray in Object.cc, which allows attackers to cause a denial of service via a crafted file.

  • CVE-2017-9406MedJun 2, 2017
    affected < 0.24.4-14.3.1fixed 0.24.4-14.3.1

    In Poppler 0.54.0, a memory leak vulnerability was found in the function gmalloc in gmem.cc, which allows attackers to cause a denial of service via a crafted file.

  • CVE-2017-7511MedMay 30, 2017
    affected < 0.43.0-16.5.1fixed 0.43.0-16.5.1

    poppler since version 0.17.3 has been vulnerable to NULL pointer dereference in pdfunite triggered by specially crafted documents.

  • CVE-2017-9083MedMay 19, 2017
    affected < 0.24.4-14.3.1fixed 0.24.4-14.3.1

    poppler 0.54.0, as used in Evince and other products, has a NULL pointer dereference in the JPXStream::readUByte function in JPXStream.cc. For example, the perf_test utility will crash (segmentation fault) when parsing an invalid PDF file.