Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.10.2019.0245
Category:Mageia Linux Local Security Checks
Title:Mageia: Security Advisory (MGASA-2019-0245)
Summary:The remote host is missing an update for the 'poppler' package(s) announced via the MGASA-2019-0245 advisory.
Description:Summary:
The remote host is missing an update for the 'poppler' package(s) announced via the MGASA-2019-0245 advisory.

Vulnerability Insight:
Updated poppler packages fix security vulnerabilities

Poppler 0.74.0 has a heap-based buffer over-read in the CairoRescaleBox.cc
downsample_row_box_filter function. (CVE-2019-9631)

PDFDoc::markObject in PDFDoc.cc in Poppler 0.74.0 mishandles dict marking,
leading to stack consumption in the function Dict::find() located at
Dict.cc, which can (for example) be triggered by passing a crafted pdf
file to the pdfunite binary. (CVE-2019-9903)

An issue was discovered in Poppler 0.74.0. There is a heap-based buffer
over-read in the function Splash::blitTransparent at splash/Splash.cc.
(CVE-2019-10872)

An issue was discovered in Poppler 0.74.0. There is a NULL pointer
dereference in the function SplashClip::clipAALine at splash/SplashClip.cc.
(CVE-2019-10873)

In Poppler through 0.76.1, there is a heap-based buffer over-read in
JPXStream::init in JPEG2000Stream.cc via data with inconsistent heights
or widths. (CVE-2019-12293)

An issue was discovered in Poppler through 0.78.0. There is a
divide-by-zero error in the function SplashOutputDev::tilingPatternFill
at SplashOutputDev.cc. (CVE-2019-14494)

Affected Software/OS:
'poppler' package(s) on Mageia 7.

Solution:
Please install the updated package(s).

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2019-10872
BugTraq ID: 107862
http://www.securityfocus.com/bid/107862
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/YWS7NVFFCUY3YSTMEKZEJEU6JVUUBKHB/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/7MAWV24KRXTFODLVT46RXI27XIQFX2QR/
https://gitlab.freedesktop.org/poppler/poppler/issues/750
https://lists.debian.org/debian-lts-announce/2019/06/msg00002.html
https://lists.debian.org/debian-lts-announce/2020/07/msg00018.html
https://usn.ubuntu.com/4042-1/
Common Vulnerability Exposure (CVE) ID: CVE-2019-10873
https://gitlab.freedesktop.org/poppler/poppler/issues/748
Common Vulnerability Exposure (CVE) ID: CVE-2019-12293
BugTraq ID: 108457
http://www.securityfocus.com/bid/108457
https://gitlab.freedesktop.org/poppler/poppler/issues/768
RedHat Security Advisories: RHSA-2019:2713
https://access.redhat.com/errata/RHSA-2019:2713
Common Vulnerability Exposure (CVE) ID: CVE-2019-14494
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AHYAM32PALHQXL3O4DKIJ3EJB6AKBOVC/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DLAQBLBIIL3A5XZQYR4MG3Z4LIPIC42P/
https://gitlab.freedesktop.org/poppler/poppler/issues/802
https://gitlab.freedesktop.org/poppler/poppler/merge_requests/317
https://lists.debian.org/debian-lts-announce/2020/11/msg00014.html
https://lists.debian.org/debian-lts-announce/2022/09/msg00030.html
https://usn.ubuntu.com/4091-1/
Common Vulnerability Exposure (CVE) ID: CVE-2019-9631
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZWP5XSUG6GNRI75NYKF53KIB2CZY6QQ6/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JQ6RABASMSIMMWMDZTP6ZWUWZPTBSVB5/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6OSCOYM3AMFFBJWSBWY6VJVLNE5JD7YS/
https://gitlab.freedesktop.org/poppler/poppler/issues/736
https://lists.debian.org/debian-lts-announce/2019/04/msg00011.html
RedHat Security Advisories: RHSA-2019:2022
https://access.redhat.com/errata/RHSA-2019:2022
Common Vulnerability Exposure (CVE) ID: CVE-2019-9903
BugTraq ID: 107560
http://www.securityfocus.com/bid/107560
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XGYLZZ4DZUDBQEGCNDWSZPSFNNZJF4S6/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XWWVIYFXM74KJFIDHP4W67HR4FRF2LDE/
https://gitlab.freedesktop.org/poppler/poppler/issues/741
https://research.loginsoft.com/bugs/stack-based-buffer-overflows-in-dictfind-poppler-0-74-0/
CopyrightCopyright (C) 2022 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.