RHSA-2020:1074MediumCVSS 6.6
Red Hat Security Advisory: poppler and evince security update
🔗 CVE IDs covered (5)
📋 Description
CVE-2018-21009 — poppler: integer overflow in Parser::makeStream in Parser.cc CVE-2019-9959 — poppler: integer overflow in JPXStream::init function leading to memory consumption CVE-2019-10871 — poppler: heap-based buffer over-read in function PSOutputDev::checkPageSlice in PSOutputDev.cc CVE-2019-11459 — evince: uninitialized memory use in function tiff_document_render() and tiff_document_get_thumbnail() CVE-2019-12293 — poppler: heap-based buffer over-read in JPXStream::init in JPEG2000Stream.cc
🔗 References (9)
- selfhttps://access.redhat.com/errata/RHSA-2020:1074
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/7.8_release_notes/index
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1696636
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1713582
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1716295
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1732340
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1753850
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2020/rhsa-2020_1074.json