ELSA-2019-2713

ELSA-2019-2713 - poppler security update

Type:SECURITY
Severity:MODERATE
Release Date:2019-09-12

Description


[0.66.0-11.el8_0.12]
- Ignore dict Length if it is broken
- Resolves: #1741146

[0.66.0-11.el8_0.11]
- Check whether input is RGB in PSOutputDev::checkPageSlice()
- (also when using '-optimizecolorspace' flag)
- Resolves: #1741145

[0.66.0-11.el8_0.10]
- Fail gracefully if not all components of JPEG2000Stream
- have the same size
- Resolves: #1740612

[0.66.0-11.el8_0.9]
- Fix stack overflow on broken file
- Resolves: #1717867

[0.66.0-11.el8_0.8]
- Constrain number of cycles in rescale filter
- Compute correct coverage values for box filter
- Resolves: #1717866

[0.66.0-11.el8_0.7]
- Fix possible crash on broken files in ImageStream::getLine()
- Resolves: #1717803

[0.66.0-11.el8_0.6]
- Move the fileSpec.dictLookup call inside fileSpec.isDict if
- Resolves: #1717788

[0.66.0-11.el8_0.5]
- Defend against requests for negative XRef indices
- Resolves: #1717779

[0.66.0-11.el8_0.4]
- Do not try to parse into unallocated XRef entry
- Resolves: #1717790

[0.66.0-11.el8_0.3]
- Avoid global display profile state becoming an uncontrolled
- memory leak
- Resolves: #1717776

[0.66.0-11.el8_0.2]
- Check Catalog from XRef for being a Dict
- Resolves: #1690480

[0.66.0-11.el8_0.1]
- Do not try to construct invalid rich media annotation assets
- Resolves: #1690478

[0.66.0-11]
- Fix tiling patterns when pattern cell is too far
- Resolves: #1644094


Related CVEs


CVE-2018-18897
CVE-2018-20481
CVE-2018-20650
CVE-2018-20662
CVE-2019-7310
CVE-2019-9200
CVE-2019-9631
CVE-2018-20551
CVE-2019-9903
CVE-2019-9959
CVE-2019-10871
CVE-2019-12293

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 8 (aarch64) poppler-0.66.0-11.el8_0.12.src.rpm9ef6e9cbe9cb717861602bdbc9d7e7e7-
poppler-0.66.0-11.el8_0.12.aarch64.rpm1fca34cdcfe456e3a52895e33c21a54c-
poppler-cpp-0.66.0-11.el8_0.12.aarch64.rpm70ae2d4ef192ee25d0d4530b139ddf32-
poppler-cpp-devel-0.66.0-11.el8_0.12.aarch64.rpm589110ac33d5b28f12e5e5b95a4b398d-
poppler-devel-0.66.0-11.el8_0.12.aarch64.rpm75fad237744cece7230ed787ca0fefb1-
poppler-glib-0.66.0-11.el8_0.12.aarch64.rpmb06c6f0904cd6ab9cf4b94757affe78e-
poppler-glib-devel-0.66.0-11.el8_0.12.aarch64.rpm66a7fe14dcbf4a9ab659c12f3dc2abdd-
poppler-qt5-0.66.0-11.el8_0.12.aarch64.rpm01bbdedd2318fe9e446b0d4cda17939e-
poppler-qt5-devel-0.66.0-11.el8_0.12.aarch64.rpm4c35ba8cc5bff18bcf40d3dde46d01dc-
poppler-utils-0.66.0-11.el8_0.12.aarch64.rpmbfefbb274b984812ad09986c6e77fffa-
Oracle Linux 8 (x86_64) poppler-0.66.0-11.el8_0.12.src.rpm9ef6e9cbe9cb717861602bdbc9d7e7e7-
poppler-0.66.0-11.el8_0.12.i686.rpmce10bb0f11f8e5f82b9a020e1890fe8c-
poppler-0.66.0-11.el8_0.12.x86_64.rpmce18c67d4acc53d864b856c4e6dbab49-
poppler-cpp-0.66.0-11.el8_0.12.i686.rpm812fa2d64a1ff7c359a7787f69160ef0-
poppler-cpp-0.66.0-11.el8_0.12.x86_64.rpm850df407e8fa089bd8b9756807cb2fa3-
poppler-cpp-devel-0.66.0-11.el8_0.12.i686.rpm06aaa5d3892702224cf1b88692375cda-
poppler-cpp-devel-0.66.0-11.el8_0.12.x86_64.rpmf405d9e047a3fabd36cbadf5e3bc89cf-
poppler-devel-0.66.0-11.el8_0.12.i686.rpm19552e67c26b446cd0bd16652f138d22-
poppler-devel-0.66.0-11.el8_0.12.x86_64.rpm61a96b39071503296e6abc7fd3d8813d-
poppler-glib-0.66.0-11.el8_0.12.i686.rpm955ab112ff656932139fe912a6f432d3-
poppler-glib-0.66.0-11.el8_0.12.x86_64.rpm8616c573a154c8effd6c8bb5db82592b-
poppler-glib-devel-0.66.0-11.el8_0.12.i686.rpm662e807d0a8a8d5c9abad1ee26450af7-
poppler-glib-devel-0.66.0-11.el8_0.12.x86_64.rpm0ad8f0963772157b4a10db8e09025986-
poppler-qt5-0.66.0-11.el8_0.12.i686.rpm9d5564b367fc420366d26003865b6bbb-
poppler-qt5-0.66.0-11.el8_0.12.x86_64.rpmf7a774dc3fc39bbd05d619a85ca80cf5-
poppler-qt5-devel-0.66.0-11.el8_0.12.i686.rpm4adb0d790b1d462966825e71986d649b-
poppler-qt5-devel-0.66.0-11.el8_0.12.x86_64.rpmcb60b825dfd22d15a54f469dad8631eb-
poppler-utils-0.66.0-11.el8_0.12.x86_64.rpmf927a45aa96c6f0b57a90ecb11233dd8-



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete