Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 670880 (CVE-2018-19149)

Summary: <app-text/poppler-0.70.0: Null pointer
Product: Gentoo Security Reporter: Michael Boyle <boylemic>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: RESOLVED FIXED    
Severity: normal CC: printing, reavertm, vk-gentoo-bugs
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
Whiteboard: B3 [glsa+ cve]
Package list:
Runtime testing required: ---
Bug Depends on: 670222, 674666    
Bug Blocks:    

Description Michael Boyle 2018-11-11 02:10:15 UTC
Poppler before 0.70.0 has a NULL pointer dereference in _poppler_attachment_new when called from poppler_annot_file_attachment_get_attachment.
Comment 1 Vlad K. 2018-11-11 12:39:48 UTC
* More info:

  https://www.openwall.com/lists/oss-security/2018/11/10/1

--
Gentoo Security Scout
Vladimir Krstulja
Comment 2 Vlad K. 2018-11-11 12:47:58 UTC
* Better URL, upstream issue

  https://gitlab.freedesktop.org/poppler/poppler/issues/664

--
Gentoo Security Scout
Vladimir Krstulja
Comment 3 Yury German Gentoo Infrastructure gentoo-dev 2018-11-11 15:02:21 UTC
This has been fixed in 0.70.0
Comment 4 Andreas Sturmlechner gentoo-dev 2019-03-03 01:03:25 UTC
Cleanup done.
Comment 5 GLSAMaker/CVETool Bot gentoo-dev 2019-04-02 04:22:52 UTC
This issue was resolved and addressed in
 GLSA 201904-04 at https://security.gentoo.org/glsa/201904-04
by GLSA coordinator Aaron Bauman (b-man).