{"id":"SUSE-SU-2023:2907-1","summary":"Security update for poppler","details":"This update for poppler fixes the following issues:\n\n  - CVE-2022-27337: Fixed a logic error in the Hints::Hints function which can cause denial of service (bsc#1199272).\n  - CVE-2018-21009: Fixed integer overflow in Parser:makeStream in Parser.cc (bsc#1149635).\n  - CVE-2019-12293: Fixed heap-based buffer over-read in JPXStream:init in JPEG2000Stream.cc (bsc#1136105).\n  - CVE-2018-20481: Fixed memory leak in GfxColorSpace:setDisplayProfile in GfxState.cc (bsc#1114966).\n  - CVE-2019-7310: Fixed a heap-based buffer over-read allows remote attackers to cause DOS via a special crafted PDF (bsc#1124150).\n  - CVE-2018-13988: Fixed buffer overflow in pdfunite (bsc#1102531).\n  - CVE-2018-16646: Fixed infinite recursion in poppler/Parser.cc:Parser::getObj() function (bsc#1107597).\n  - CVE-2018-19058: Fixed reachable abort in Object.h leading to denial of service (bsc#1115187).\n  - CVE-2018-19059: Fixed out-of-bounds read in EmbFile:save2 in FileSpec.cc leading to denial of service (bsc#1115186).\n  - CVE-2018-19060: Fixed NULL pointer dereference in goo/GooString.h leading to denial of service (bsc#1115185).\n  - CVE-2018-19149: Fixed NULL pointer dereference in _poppler_attachment_new when called from poppler_annot_file_attachment_get_attachment (bsc#1115626).\n  - CVE-2017-18267: Fixed denial of service (infinite recursion) via a crafted PDF file (bsc#1092945).\n  - CVE-2018-20650: Fixed issue where a reachable Object in dictLookup assertion allows attackers to cause DOS (bsc#1120939).\n\n","modified":"2026-03-11T07:24:24.252145Z","published":"2023-07-20T08:20:53Z","related":["CVE-2017-18267","CVE-2018-13988","CVE-2018-16646","CVE-2018-18897","CVE-2018-19058","CVE-2018-19059","CVE-2018-19060","CVE-2018-19149","CVE-2018-20481","CVE-2018-20650","CVE-2018-21009","CVE-2019-12293","CVE-2019-7310","CVE-2022-27337"],"upstream":["CVE-2017-18267","CVE-2018-13988","CVE-2018-16646","CVE-2018-18897","CVE-2018-19058","CVE-2018-19059","CVE-2018-19060","CVE-2018-19149","CVE-2018-20481","CVE-2018-20650","CVE-2018-21009","CVE-2019-12293","CVE-2019-7310","CVE-2022-27337"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2023/suse-su-20232907-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1092945"},{"type":"REPORT","url":"https://bugzilla.suse.com/1102531"},{"type":"REPORT","url":"https://bugzilla.suse.com/1107597"},{"type":"REPORT","url":"https://bugzilla.suse.com/1114966"},{"type":"REPORT","url":"https://bugzilla.suse.com/1115185"},{"type":"REPORT","url":"https://bugzilla.suse.com/1115186"},{"type":"REPORT","url":"https://bugzilla.suse.com/1115187"},{"type":"REPORT","url":"https://bugzilla.suse.com/1115626"},{"type":"REPORT","url":"https://bugzilla.suse.com/1120939"},{"type":"REPORT","url":"https://bugzilla.suse.com/1124150"},{"type":"REPORT","url":"https://bugzilla.suse.com/1136105"},{"type":"REPORT","url":"https://bugzilla.suse.com/1149635"},{"type":"REPORT","url":"https://bugzilla.suse.com/1199272"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-18267"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-13988"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-16646"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-18897"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-19058"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-19059"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-19060"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-19149"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-20481"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-20650"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-21009"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-12293"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-7310"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-27337"}],"affected":[{"package":{"name":"poppler","ecosystem":"SUSE:Linux Enterprise Software Development Kit 12 SP5","purl":"pkg:rpm/suse/poppler&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.43.0-16.25.1"}]}],"ecosystem_specific":{"binaries":[{"libpoppler-devel":"0.43.0-16.25.1","libpoppler-glib-devel":"0.43.0-16.25.1","libpoppler-qt4-devel":"0.43.0-16.25.1","typelib-1_0-Poppler-0_18":"0.43.0-16.25.1","libpoppler-cpp0":"0.43.0-16.25.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:2907-1.json"}},{"package":{"name":"poppler-qt","ecosystem":"SUSE:Linux Enterprise Software Development Kit 12 SP5","purl":"pkg:rpm/suse/poppler-qt&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.43.0-16.25.1"}]}],"ecosystem_specific":{"binaries":[{"libpoppler-glib-devel":"0.43.0-16.25.1","libpoppler-qt4-devel":"0.43.0-16.25.1","typelib-1_0-Poppler-0_18":"0.43.0-16.25.1","libpoppler-cpp0":"0.43.0-16.25.1","libpoppler-devel":"0.43.0-16.25.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:2907-1.json"}},{"package":{"name":"poppler","ecosystem":"SUSE:Linux Enterprise Server 12 SP5","purl":"pkg:rpm/suse/poppler&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.43.0-16.25.1"}]}],"ecosystem_specific":{"binaries":[{"libpoppler-glib8":"0.43.0-16.25.1","libpoppler-qt4-4":"0.43.0-16.25.1","libpoppler60":"0.43.0-16.25.1","poppler-tools":"0.43.0-16.25.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:2907-1.json"}},{"package":{"name":"poppler-qt","ecosystem":"SUSE:Linux Enterprise Server 12 SP5","purl":"pkg:rpm/suse/poppler-qt&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.43.0-16.25.1"}]}],"ecosystem_specific":{"binaries":[{"libpoppler60":"0.43.0-16.25.1","poppler-tools":"0.43.0-16.25.1","libpoppler-glib8":"0.43.0-16.25.1","libpoppler-qt4-4":"0.43.0-16.25.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:2907-1.json"}},{"package":{"name":"poppler","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP5","purl":"pkg:rpm/suse/poppler&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.43.0-16.25.1"}]}],"ecosystem_specific":{"binaries":[{"libpoppler-glib8":"0.43.0-16.25.1","libpoppler-qt4-4":"0.43.0-16.25.1","libpoppler60":"0.43.0-16.25.1","poppler-tools":"0.43.0-16.25.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:2907-1.json"}},{"package":{"name":"poppler-qt","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP5","purl":"pkg:rpm/suse/poppler-qt&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.43.0-16.25.1"}]}],"ecosystem_specific":{"binaries":[{"libpoppler-glib8":"0.43.0-16.25.1","libpoppler-qt4-4":"0.43.0-16.25.1","libpoppler60":"0.43.0-16.25.1","poppler-tools":"0.43.0-16.25.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:2907-1.json"}}],"schema_version":"1.7.5"}