VYPR

rpm package

suse/poppler&distro=SUSE Linux Enterprise Software Development Kit 12 SP2

pkg:rpm/suse/poppler&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP2

Vulnerabilities (6)

  • CVE-2017-9776HigJun 22, 2017
    affected < 0.43.0-16.5.1fixed 0.43.0-16.5.1

    Integer overflow leading to Heap buffer overflow in JBIG2Stream.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PDF document.

  • CVE-2017-9775MedJun 22, 2017
    affected < 0.43.0-16.5.1fixed 0.43.0-16.5.1

    Stack buffer overflow in GfxState.cc in pdftocairo in Poppler before 0.56 allows remote attackers to cause a denial of service (application crash) via a crafted PDF document.

  • CVE-2017-7515MedJun 6, 2017
    affected < 0.43.0-16.5.1fixed 0.43.0-16.5.1

    poppler through version 0.55.0 is vulnerable to an uncontrolled recursion in pdfunite resulting into potential denial-of-service.

  • CVE-2017-9408MedJun 2, 2017
    affected < 0.43.0-16.5.1fixed 0.43.0-16.5.1

    In Poppler 0.54.0, a memory leak vulnerability was found in the function Object::initArray in Object.cc, which allows attackers to cause a denial of service via a crafted file.

  • CVE-2017-9406MedJun 2, 2017
    affected < 0.43.0-16.5.1fixed 0.43.0-16.5.1

    In Poppler 0.54.0, a memory leak vulnerability was found in the function gmalloc in gmem.cc, which allows attackers to cause a denial of service via a crafted file.

  • CVE-2017-7511MedMay 30, 2017
    affected < 0.43.0-16.5.1fixed 0.43.0-16.5.1

    poppler since version 0.17.3 has been vulnerable to NULL pointer dereference in pdfunite triggered by specially crafted documents.