{"id":"SUSE-SU-2023:4546-1","summary":"Security update for poppler","details":"This update for poppler fixes the following issues:\n\n- CVE-2019-9545: Fixed a potential crash due to uncontrolled recursion\n  in the JBIG parser (bsc#1128114).\n- CVE-2019-9631: Fixed an out of bounds read when converting a PDF to\n  an image (bsc#1129202).\n- CVE-2022-37052: Fixed a reachable assertion when extracting pages of\n  a PDf file (bsc#1214726).\n- CVE-2020-36023: Fixed a stack bugger overflow in\n  FoFiType1C:cvtGlyph (bsc#1214256).\n- CVE-2019-14292: Fixed an out of bounds read in GfxState.cc\n  (bsc#1143570).\n- CVE-2022-48545: Fixed an infinite recursion in\n  Catalog::findDestInTree which can cause denial of service\n  (bsc#1214723).\n","modified":"2026-03-11T07:25:19.502866Z","published":"2023-11-24T08:11:55Z","related":["CVE-2019-14292","CVE-2019-9545","CVE-2019-9631","CVE-2020-36023","CVE-2022-37052","CVE-2022-48545"],"upstream":["CVE-2019-14292","CVE-2019-9545","CVE-2019-9631","CVE-2020-36023","CVE-2022-37052","CVE-2022-48545"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2023/suse-su-20234546-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1128114"},{"type":"REPORT","url":"https://bugzilla.suse.com/1129202"},{"type":"REPORT","url":"https://bugzilla.suse.com/1143570"},{"type":"REPORT","url":"https://bugzilla.suse.com/1214256"},{"type":"REPORT","url":"https://bugzilla.suse.com/1214723"},{"type":"REPORT","url":"https://bugzilla.suse.com/1214726"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-14292"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-9545"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-9631"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-36023"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-37052"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-48545"}],"affected":[{"package":{"name":"poppler","ecosystem":"SUSE:Linux Enterprise Software Development Kit 12 SP5","purl":"pkg:rpm/suse/poppler&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.24.4-14.41.1"}]}],"ecosystem_specific":{"binaries":[{"libpoppler44":"0.24.4-14.41.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2023:4546-1.json"}}],"schema_version":"1.7.5"}