MGASA-2023-0348 - Updated poppler packages fix a security vulnerability

Publication date: 16 Dec 2023
URL: https://advisories.mageia.org/MGASA-2023-0348.html
Type: security
Affected Mageia releases: 9
CVE: CVE-2023-34872

A vulnerability in Outline.cc for Poppler prior to 23.06.0 allows a
remote attacker to cause a Denial of Service (DoS) (crash) via a crafted
PDF file in OutlineItem::open. (CVE-2023-34872)
This update fixes that issue.

References:
- https://bugs.mageia.org/show_bug.cgi?id=32600
- https://bugzilla.redhat.com/show_bug.cgi?id=2227884
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JQ3NYJ43U2MA7COKGMJDARZUAAOP45D4/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-34872

SRPMS:
- 9/core/poppler-23.02.0-1.1.mga9

Mageia 2023-0348: poppler security update

A vulnerability in Outline.cc for Poppler prior to 23.06.0 allows a remote attacker to cause a Denial of Service (DoS) (crash) via a crafted PDF file in OutlineItem::open

Summary

A vulnerability in Outline.cc for Poppler prior to 23.06.0 allows a remote attacker to cause a Denial of Service (DoS) (crash) via a crafted PDF file in OutlineItem::open. (CVE-2023-34872) This update fixes that issue.

References

- https://bugs.mageia.org/show_bug.cgi?id=32600

- https://bugzilla.redhat.com/show_bug.cgi?id=2227884

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JQ3NYJ43U2MA7COKGMJDARZUAAOP45D4/

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-34872

Resolution

MGASA-2023-0348 - Updated poppler packages fix a security vulnerability

SRPMS

- 9/core/poppler-23.02.0-1.1.mga9

Severity
Publication date: 16 Dec 2023
URL: https://advisories.mageia.org/MGASA-2023-0348.html
Type: security
CVE: CVE-2023-34872

Related News