MGASA-2019-0419

Source
https://advisories.mageia.org/MGASA-2019-0419.html
Import Source
https://advisories.mageia.org/MGASA-2019-0419.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2019-0419
Related
Published
2019-12-31T16:51:17Z
Modified
2019-12-31T16:33:21Z
Summary
Updated pdfresurrect packages fix security vulnerabilities
Details

Updated pdfresurrect package fixes security vulnerabilities:

A vulnerability was found in PDFResurrect 0.15 has a buffer overflow via a crafted PDF file because data associated with startxref and %%EOF is mishandled (CVE-2019-14267).

An issue was discovered in PDFResurrect before 0.18. pdfloadpages_kids in pdf.c doesn't validate a certain size value, which leads to a malloc failure and out-of-bounds write (CVE-2019-14934).

References
Credits

Affected packages

Mageia:7 / pdfresurrect

Package

Name
pdfresurrect
Purl
pkg:rpm/mageia/pdfresurrect?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.18-1.mga7

Ecosystem specific

{
    "section": "core"
}