UbuntuUpdates.org

Package "libpoppler134"

Name: libpoppler134

Description:

PDF rendering library

Latest version: 24.02.0-1ubuntu9.2
Release: noble (24.04)
Level: updates
Repository: main
Head package: poppler
Homepage: https://poppler.freedesktop.org/

Links


Download "libpoppler134"


Other versions of "libpoppler134" in Noble

Repository Area Version
base main 24.02.0-1ubuntu9
security main 24.02.0-1ubuntu9.2

Changelog

Version: 24.02.0-1ubuntu9.2 2025-01-16 19:07:06 UTC

  poppler (24.02.0-1ubuntu9.2) noble-security; urgency=medium

  * SECURITY UPDATE: Out-of-bounds read in pdf file parsing.
    - debian/patches/CVE-2024-56378.patch: Add checks to unlikely and destPtr
      in poppler/JBIG2Stream.cc.
    - CVE-2024-56378

 -- Hlib Korzhynskyy <email address hidden> Tue, 14 Jan 2025 12:26:08 -0330

Source diff to previous version
CVE-2024-56378 libpoppler.so in Poppler through 24.12.0 has an out-of-bounds read vulnerability within the JBIG2Bitmap::combine function in JBIG2Stream.cc.

Version: 24.02.0-1ubuntu9.1 2024-07-25 01:07:26 UTC

  poppler (24.02.0-1ubuntu9.1) noble-security; urgency=medium

  * SECURITY UPDATE: Denial of service
    - debian/patches/CVE-2024-6239.patch: fix crash in broken
      documents when using -dests in utils/pdfinfo.c.
    - CVE-2024-6239

 -- Leonidas Da Silva Barbosa <email address hidden> Wed, 26 Jun 2024 09:54:47 -0300

CVE-2024-6239 A flaw was found in the Poppler's Pdfinfo utility. This issue occurs when using -dests parameter with pdfinfo utility. By using certain malformed inp



About   -   Send Feedback to @ubuntu_updates