Security
Headlines
HeadlinesLatestCVEs

Headline

Ubuntu Security Notice USN-5606-2

Ubuntu Security Notice 5606-2 - USN-5606-1 fixed a vulnerability in poppler. Unfortunately it was missing a commit to fix it properly. This update provides the corresponding fix for Ubuntu 18.04 LTS and Ubuntu 16.04 ESM. It was discovered that poppler incorrectly handled certain PDF. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code.

Packet Storm
#vulnerability#ubuntu#dos#perl#pdf

=========================================================================
Ubuntu Security Notice USN-5606-2
September 14, 2022

poppler regression

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 18.04 LTS
  • Ubuntu 16.04 ESM

Summary:

USN-5606-1 caused a regression in poppler.

Software Description:

  • poppler: PDF rendering library

Details:

USN-5606-1 fixed a vulnerability in poppler. Unfortunately it was missing a
commit to fix it properly. This update provides
the corresponding fix for Ubuntu 18.04 LTS and Ubuntu 16.04 ESM.

We apologize for the inconvenience.

Original advisory details:

It was discovered that poppler incorrectly handled certain
PDF. An attacker could possibly use this issue to cause a
denial of service or execute arbitrary code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS:
libpoppler-private-dev 0.62.0-2ubuntu2.14
libpoppler73 0.62.0-2ubuntu2.14
poppler-utils 0.62.0-2ubuntu2.14

Ubuntu 16.04 ESM:
libpoppler-private-dev 0.41.0-0ubuntu1.16+esm2
libpoppler58 0.41.0-0ubuntu1.16+esm2
poppler-utils 0.41.0-0ubuntu1.16+esm2

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-5606-2
https://ubuntu.com/security/notices/USN-5606-1
https://launchpad.net/bugs/1989515

Package Information:
https://launchpad.net/ubuntu/+source/poppler/0.62.0-2ubuntu2.14

Packet Storm: Latest News

Ivanti EPM Agent Portal Command Execution