Bug#941776: poppler: CVE-2019-9959
carnil at debian.org
Sat Oct 5 10:18:04 BST 2019
Tags: security upstream
Control: found -1 0.71.0-5
Control: fixed -1 0.81.0-1
The following vulnerability was published for poppler.
| The JPXStream::init function in Poppler 0.78.0 and earlier doesn't
| check for negative values of stream length, leading to an Integer
| Overflow, thereby making it possible to allocate a large memory chunk
| on the heap, with a size controlled by an attacker, as demonstrated by
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
Please adjust the affected versions in the BTS as needed.
More information about the Pkg-freedesktop-maintainers