SciLinux: SLSA-2020-1074-1 Moderate: poppler and evince on SL7.x x86_64
Summary
Moderate: poppler and evince security update
Synopsis: Moderate: poppler and evince security update Advisory ID: SLSA-2020:1074-1 Issue Date: 2020-04-07 CVE Numbers: CVE-2018-21009 CVE-2019-10871 CVE-2019-9959 CVE-2019-11459 CVE-2019-12293 -- * poppler: integer overflow in Parser::makeStream in Parser.cc * poppler: heap-based buffer over-read in function PSOutputDev::checkPageSlice in PSOutputDev.cc * poppler: heap-based buffer over-read in JPXStream::init in JPEG2000Stream.cc * poppler: integer overflow in JPXStream::init function leading to memory consumption * evince: uninitialized memory use in function tiff_document_render() and tiff_document_get_thumbnail() -- SL7 x86_64 evince-libs-3.28.2-9.el7.i686.rpm poppler-glib-0.26.5-42.el7.i686.rpm poppler-qt-0.26.5-42.el7.i686.rpm poppler-glib-0.26.5-42.el7.x86_64.rpm evince-3.28.2-9.el7.x86_64.rpm evince-libs-3.28.2-9.el7.x86_64.rpm evince-nautilus-3.28.2-9.el7.x86_64.rpm evince-dvi-3.28.2-9.el7.x86_64.rpm poppler-0.26.5-42.el7.x86_64.rpm poppler-0.26.5-42.el7.i686.rpm poppler-qt-0.26.5-42.el7.x86_64.rpm poppler-utils-0.26.5-42.el7.x86_64.rpm evince-debuginfo-3.28.2-9.el7.i686.rpm evince-debuginfo-3.28.2-9.el7.x86_64.rpm poppler-debuginfo-0.26.5-42.el7.i686.rpm poppler-debuginfo-0.26.5-42.el7.x86_64.rpm evince-browser-plugin-3.28.2-9.el7.x86_64.rpm evince-devel-3.28.2-9.el7.i686.rpm evince-devel-3.28.2-9.el7.x86_64.rpm poppler-cpp-0.26.5-42.el7.i686.rpm poppler-cpp-0.26.5-42.el7.x86_64.rpm poppler-cpp-devel-0.26.5-42.el7.i686.rpm poppler-cpp-devel-0.26.5-42.el7.x86_64.rpm poppler-demos-0.26.5-42.el7.x86_64.rpm poppler-devel-0.26.5-42.el7.i686.rpm poppler-devel-0.26.5-42.el7.x86_64.rpm poppler-glib-devel-0.26.5-42.el7.i686.rpm poppler-glib-devel-0.26.5-42.el7.x86_64.rpm poppler-qt-devel-0.26.5-42.el7.i686.rpm poppler-qt-devel-0.26.5-42.el7.x86_64.rpm - Scientific Linux Development Team
Moderate: poppler and evince security update