poppler 0.6.4-1ubuntu3.3 source package in Ubuntu
Changelog
poppler (0.6.4-1ubuntu3.3) hardy-security; urgency=low * SECURITY UPDATE: denial of service or arbitrary code execution via unsafe malloc usage - debian/patches/105_security_CVE-2009-3605.patch: introduce gmallocn3 in goo/gmem.{cc,h} and replace malloc calls with safe versions in glib/poppler-page.cc, poppler/{ArthurOutputDev,CairoOutputDev, GfxState,JBIG2Stream,PSOutputDev,SplashOutputDev}.cc, splash/{SplashBitmap,Splash,SplashFTFont}.cc. - CVE-2009-3605 * SECURITY UPDATE: denial of service via invalid Form Opt entry (LP: #321764) - debian/patches/106_security_CVE-2009-0755.patch: handle invalid Opt entry gracefully in poppler/Form.cc. - CVE-2009-0755 * SECURITY UPDATE: denial of service or arbitrary code execution via overflow in rowSize computation - debian/patches/107_security_CVE-2009-360x.patch: make sure width value is sane in splash/SplashBitmap.cc. - CVE-2009-3603 * SECURITY UPDATE: denial of service or arbitrary code execution via overflow in pixel buffer size calculation - debian/patches/107_security_CVE-2009-360x.patch: make sure yp value is sane in splash/Splash.cc, splash/SplashErrorCodes.h. - CVE-2009-3604 * SECURITY UPDATE: denial of service or arbitrary code execution via overflow in object stream handling - debian/patches/107_security_CVE-2009-360x.patch: limit number of nObjects in poppler/XRef.cc. - CVE-2009-3608 * SECURITY UPDATE: denial of service or arbitrary code execution via integer overflow in ImageStream::ImageStream - debian/patches/107_security_CVE-2009-360x.patch: check size of width and nComps in poppler/Stream.cc. - CVE-2009-3609 -- Marc Deslauriers <email address hidden> Mon, 19 Oct 2009 11:14:11 -0400
Upload details
- Uploaded by:
- Marc Deslauriers
- Uploaded to:
- Hardy
- Original maintainer:
- Ubuntu Development Team
- Architectures:
- any
- Section:
- devel
- Urgency:
- Low Urgency
See full publishing history Publishing
Series | Published | Component | Section |
---|
Downloads
File | Size | SHA-256 Checksum |
---|---|---|
poppler_0.6.4.orig.tar.gz | 1.2 MiB | 54269075e4d611a61792a374986e920744c8ca39c2df45911233873c7e714354 |
poppler_0.6.4-1ubuntu3.3.diff.gz | 21.5 KiB | 7b7cf555bb9927b54c23e2a40443b4a14548185e56d97f5b8b2002ffebbce4cf |
poppler_0.6.4-1ubuntu3.3.dsc | 1.2 KiB | 99e36d1bc737d4daa5e1028c76ec879a45764178d21933b2b322602bc59a0d18 |
Available diffs
Binary packages built by this source
- libpoppler-dev: No summary available for libpoppler-dev in ubuntu hardy.
No description available for libpoppler-dev in ubuntu hardy.
- libpoppler-glib-dev: No summary available for libpoppler-glib-dev in ubuntu hardy.
No description available for libpoppler-glib-dev in ubuntu hardy.
- libpoppler-glib2: No summary available for libpoppler-glib2 in ubuntu hardy.
No description available for libpoppler-glib2 in ubuntu hardy.
- libpoppler-qt-dev: No summary available for libpoppler-qt-dev in ubuntu hardy.
No description available for libpoppler-qt-dev in ubuntu hardy.
- libpoppler-qt2: No summary available for libpoppler-qt2 in ubuntu hardy.
No description available for libpoppler-qt2 in ubuntu hardy.
- libpoppler-qt4-2: No summary available for libpoppler-qt4-2 in ubuntu hardy.
No description available for libpoppler-qt4-2 in ubuntu hardy.
- libpoppler-qt4-dev: No summary available for libpoppler-qt4-dev in ubuntu hardy.
No description available for libpoppler-qt4-dev in ubuntu hardy.
- libpoppler2: No summary available for libpoppler2 in ubuntu hardy.
No description available for libpoppler2 in ubuntu hardy.
- poppler-utils: No summary available for poppler-utils in ubuntu hardy.
No description available for poppler-utils in ubuntu hardy.