{"id":"SUSE-SU-2023:4362-1","summary":"Security update for poppler","details":"This update for poppler fixes the following issues:\n\n- CVE-2019-9545: Fixed a potential crash due to uncontrolled recursion\n  in the JBIG parser (bsc#1128114).\n- CVE-2019-9631: Fixed an out of bounds read when converting a PDF to\n  an image (bsc#1129202).\n- CVE-2022-37052: Fixed a reachable assertion when extracting pages of\n  a PDf file (bsc#1214726).\n- CVE-2020-36023: Fixed a stack bugger overflow in\n  FoFiType1C:cvtGlyph (bsc#1214256).\n- CVE-2019-13287: Fixed an out-of-bounds read vulnerability in the\n  function SplashXPath:strokeAdjust (bsc#1140745).\n- CVE-2018-18456: Fixed a stack-based buffer over-read via a crafted\n  pdf file (bsc#1112428).\n- CVE-2018-18454: Fixed heap-based buffer over-read via a crafted pdf\n  file (bsc#1112424).\n- CVE-2019-14292: Fixed an out of bounds read in GfxState.cc\n  (bsc#1143570).\n- CVE-2022-48545: Fixed an infinite recursion in\n  Catalog::findDestInTree which can cause denial of service\n  (bsc#1214723).\n","modified":"2026-03-11T07:25:11.076650Z","published":"2023-11-03T12:48:58Z","related":["CVE-2018-18454","CVE-2018-18456","CVE-2019-13287","CVE-2019-14292","CVE-2019-9545","CVE-2019-9631","CVE-2020-36023","CVE-2022-37052","CVE-2022-48545"],"upstream":["CVE-2018-18454","CVE-2018-18456","CVE-2019-13287","CVE-2019-14292","CVE-2019-9545","CVE-2019-9631","CVE-2020-36023","CVE-2022-37052","CVE-2022-48545"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2023/suse-su-20234362-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1112424"},{"type":"REPORT","url":"https://bugzilla.suse.com/1112428"},{"type":"REPORT","url":"https://bugzilla.suse.com/1128114"},{"type":"REPORT","url":"https://bugzilla.suse.com/1129202"},{"type":"REPORT","url":"https://bugzilla.suse.com/1140745"},{"type":"REPORT","url":"https://bugzilla.suse.com/1143570"},{"type":"REPORT","url":"https://bugzilla.suse.com/1214256"},{"type":"REPORT","url":"https://bugzilla.suse.com/1214723"},{"type":"REPORT","url":"https://bugzilla.suse.com/1214726"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-18454"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-18456"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13287"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-14292"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-9545"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-9631"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-36023"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-37052"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-48545"}],"affected":[{"package":{"name":"poppler","ecosystem":"SUSE:Linux Enterprise Software Development Kit 12 SP5","purl":"pkg:rpm/suse/poppler&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.43.0-16.40.1"}]}],"ecosystem_specific":{"binaries":[{"libpoppler-devel":"0.43.0-16.40.1","libpoppler-glib-devel":"0.43.0-16.40.1","libpoppler-qt4-devel":"0.43.0-16.40.1","typelib-1_0-Poppler-0_18":"0.43.0-16.40.1","libpoppler-cpp0":"0.43.0-16.40.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:4362-1.json"}},{"package":{"name":"poppler-qt","ecosystem":"SUSE:Linux Enterprise Software Development Kit 12 SP5","purl":"pkg:rpm/suse/poppler-qt&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.43.0-16.40.1"}]}],"ecosystem_specific":{"binaries":[{"libpoppler-devel":"0.43.0-16.40.1","libpoppler-glib-devel":"0.43.0-16.40.1","libpoppler-qt4-devel":"0.43.0-16.40.1","typelib-1_0-Poppler-0_18":"0.43.0-16.40.1","libpoppler-cpp0":"0.43.0-16.40.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:4362-1.json"}},{"package":{"name":"poppler","ecosystem":"SUSE:Linux Enterprise Server 12 SP5","purl":"pkg:rpm/suse/poppler&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.43.0-16.40.1"}]}],"ecosystem_specific":{"binaries":[{"libpoppler-glib8":"0.43.0-16.40.1","libpoppler-qt4-4":"0.43.0-16.40.1","libpoppler60":"0.43.0-16.40.1","poppler-tools":"0.43.0-16.40.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:4362-1.json"}},{"package":{"name":"poppler-qt","ecosystem":"SUSE:Linux Enterprise Server 12 SP5","purl":"pkg:rpm/suse/poppler-qt&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.43.0-16.40.1"}]}],"ecosystem_specific":{"binaries":[{"libpoppler-glib8":"0.43.0-16.40.1","libpoppler-qt4-4":"0.43.0-16.40.1","libpoppler60":"0.43.0-16.40.1","poppler-tools":"0.43.0-16.40.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:4362-1.json"}},{"package":{"name":"poppler","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP5","purl":"pkg:rpm/suse/poppler&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.43.0-16.40.1"}]}],"ecosystem_specific":{"binaries":[{"libpoppler-glib8":"0.43.0-16.40.1","libpoppler-qt4-4":"0.43.0-16.40.1","libpoppler60":"0.43.0-16.40.1","poppler-tools":"0.43.0-16.40.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:4362-1.json"}},{"package":{"name":"poppler-qt","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP5","purl":"pkg:rpm/suse/poppler-qt&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.43.0-16.40.1"}]}],"ecosystem_specific":{"binaries":[{"libpoppler-glib8":"0.43.0-16.40.1","libpoppler-qt4-4":"0.43.0-16.40.1","libpoppler60":"0.43.0-16.40.1","poppler-tools":"0.43.0-16.40.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:4362-1.json"}}],"schema_version":"1.7.5"}