SUSE-SU-2019:1849-1

Source
https://www.suse.com/support/update/announcement/2019/suse-su-20191849-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2019:1849-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2019:1849-1
Related
Published
2019-07-15T12:47:27Z
Modified
2019-07-15T12:47:27Z
Summary
Security update for podofo
Details

This update for podofo fixes the following issues:

Security issues fixed:

  • CVE-2017-8054: Fixed a vulnerability in PdfPagesTree::GetPageNodeFromArray function which could allow remote attackers to cause Denial of Service (bsc#1035596).
  • CVE-2018-5783: Fixed an uncontrolled memory allocation in PdfVecObjects::Reserve function (bsc#1076962).
  • CVE-2018-11255: Fixed a null pointer dereference in PdfPage::GetPageNumber() function which could lead to Denial of Service (bsc#1096890).
  • CVE-2018-20751: Fixed a null pointer dereference in crop_page function (bsc#1124357).
  • CVE-2018-12982: Fixed an invalid memory read in PdfVariant::DelayedLoad() function which could allow remote attackers to cause Denial of Service (bsc#1099720).
  • Fixed a buffer overflow in TestEncrypt function.
  • Fixed a null pointer dereference in PdfTranslator-setTarget function.
  • Fixed a heap based buffer overflow PdfVariant:DelayedLoad function.
References

Affected packages

SUSE:Linux Enterprise Desktop 12 SP4 / podofo

Package

Name
podofo
Purl
pkg:rpm/suse/podofo&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.9.2-3.9.2

Ecosystem specific

{
    "binaries": [
        {
            "libpodofo0_9_2": "0.9.2-3.9.2"
        }
    ]
}

SUSE:Linux Enterprise Software Development Kit 12 SP4 / podofo

Package

Name
podofo
Purl
pkg:rpm/suse/podofo&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.9.2-3.9.2

Ecosystem specific

{
    "binaries": [
        {
            "libpodofo-devel": "0.9.2-3.9.2"
        }
    ]
}

SUSE:Linux Enterprise Workstation Extension 12 SP4 / podofo

Package

Name
podofo
Purl
pkg:rpm/suse/podofo&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.9.2-3.9.2

Ecosystem specific

{
    "binaries": [
        {
            "libpodofo0_9_2": "0.9.2-3.9.2"
        }
    ]
}