VDB

ALINUX2-SA-2020%3A0052

ALINUX2-SA-2020%3A0052 PUBLISHED CVSS 5.900000095367432 MEDIUM

Package updates are available for Alibaba Cloud Linux 2.1903 that fix the following vulnerabilities: CVE-2018-21009: Poppler before 0.66.0 has an integer overflow in Parser::makeStream in Parser.cc. CVE-2019-10871: An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function PSOutputDev::checkPageSlice at PSOutputDev.cc. CVE-2019-11459: The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3.32.0 did not handle errors from TIFFReadRGBAImageOriented(), leading to uninitialized memory use when processing certain TIFF image files. CVE-2019-12293: In Poppler through 0.76.1, there is a heap-based buffer over-read in JPXStream::init in JPEG2000Stream.cc via data with inconsistent heights or widths. CVE-2019-9959: The JPXStream::init function in Poppler 0.78.0 and earlier doesn't check for negative values of stream length, leading to an Integer Overflow, thereby making it possible to allocate a large memory chunk on the heap, with a size controlled by an attacker, as demonstrated by pdftocairo.

Risk Scores

CVSS 3.0
5.900000095367432
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Affected Products

VendorProductVersions
Alibaba Cloudevince
Alibaba Cloudpoppler

Timeline

  • Apr 2, 2020 CVE Published
  • Apr 2, 2020 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›