MGASA-2018-0145

Source
https://advisories.mageia.org/MGASA-2018-0145.html
Import Source
https://advisories.mageia.org/MGASA-2018-0145.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2018-0145
Related
Published
2018-02-26T16:23:22Z
Modified
2018-02-26T15:55:07Z
Summary
Updated qpdf packages fix security vulnerabilities
Details

Updated qpdf packages fix security vulnerabilities:

  1. Stack overflow due to endless recursion in QPDFTokenizer::resolveLiteral()
  2. Another stack overflow / endless recursion in QPDFWriter::enqueueObject()
  3. Stack out of bounds read in iterate_rc4()
  4. heap out of bounds read (large) in Pl_Buffer::write
  5. Hang due to a pdf xref loop:

Also, the libjpeg package has been patched to provide pkgconfig files, so that cups-filters could be rebuilt against this qpdf update.

References
Credits

Affected packages