Gentoo Archives: gentoo-announce

From: Aaron Bauman <bman@g.o>
To: gentoo-announce@l.g.o
Subject: [gentoo-announce] [ GLSA 201801-17 ] Poppler: Multiple vulnerabilities
Date: Wed, 17 Jan 2018 13:44:24
Message-Id: 11963708.kDnzz4fRt3@localhost.localdomain
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 201801-17
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 https://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: Poppler: Multiple vulnerabilities
9 Date: January 17, 2018
10 Bugs: #619558, #620198, #622430, #624708, #627390
11 ID: 201801-17
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabilities have been found in Poppler, the worst of which
19 could allow the execution of arbitrary code.
20
21 Background
22 ==========
23
24 Poppler is a PDF rendering library based on the xpdf-3.0 code base.
25
26 Affected packages
27 =================
28
29 -------------------------------------------------------------------
30 Package / Vulnerable / Unaffected
31 -------------------------------------------------------------------
32 1 app-text/poppler < 0.57.0-r1 >= 0.57.0-r1
33
34 Description
35 ===========
36
37 Multiple vulnerabilities have been discovered in Poppler. Please review
38 the CVE identifiers referenced below for details.
39
40 Impact
41 ======
42
43 A remote attacker, by enticing a user to open a specially crafted PDF,
44 could execute arbitrary code or cause a Denial of Service condition.
45
46 Workaround
47 ==========
48
49 There is no known workaround at this time.
50
51 Resolution
52 ==========
53
54 All Poppler users should upgrade to the latest version:
55
56 # emerge --sync
57 # emerge --ask --oneshot --verbose ">=app-text/poppler-0.57.0-r1"
58
59 References
60 ==========
61
62 [ 1 ] CVE-2017-2820
63 https://nvd.nist.gov/vuln/detail/CVE-2017-2820
64 [ 2 ] CVE-2017-7511
65 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-7511
66 [ 3 ] CVE-2017-9083
67 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-9083
68 [ 4 ] CVE-2017-9406
69 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-9406
70 [ 5 ] CVE-2017-9408
71 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-9408
72 [ 6 ] CVE-2017-9865
73 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2017-9865
74
75 Availability
76 ============
77
78 This GLSA and any updates to it are available for viewing at
79 the Gentoo Security Website:
80
81 https://security.gentoo.org/glsa/201801-17
82
83 Concerns?
84 =========

Attachments

File name MIME type
signature.asc application/pgp-signature