Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 670880 (CVE-2018-19149) - <app-text/poppler-0.70.0: Null pointer
Summary: <app-text/poppler-0.70.0: Null pointer
Status: RESOLVED FIXED
Alias: CVE-2018-19149
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B3 [glsa+ cve]
Keywords:
Depends on: poppler-0.71.0 CVE-2018-20650
Blocks:
  Show dependency tree
 
Reported: 2018-11-11 02:10 UTC by Michael Boyle
Modified: 2019-04-02 04:22 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Michael Boyle 2018-11-11 02:10:15 UTC
Poppler before 0.70.0 has a NULL pointer dereference in _poppler_attachment_new when called from poppler_annot_file_attachment_get_attachment.
Comment 1 Vlad K. 2018-11-11 12:39:48 UTC
* More info:

  https://www.openwall.com/lists/oss-security/2018/11/10/1

--
Gentoo Security Scout
Vladimir Krstulja
Comment 2 Vlad K. 2018-11-11 12:47:58 UTC
* Better URL, upstream issue

  https://gitlab.freedesktop.org/poppler/poppler/issues/664

--
Gentoo Security Scout
Vladimir Krstulja
Comment 3 Yury German Gentoo Infrastructure gentoo-dev 2018-11-11 15:02:21 UTC
This has been fixed in 0.70.0
Comment 4 Andreas Sturmlechner gentoo-dev 2019-03-03 01:03:25 UTC
Cleanup done.
Comment 5 GLSAMaker/CVETool Bot gentoo-dev 2019-04-02 04:22:52 UTC
This issue was resolved and addressed in
 GLSA 201904-04 at https://security.gentoo.org/glsa/201904-04
by GLSA coordinator Aaron Bauman (b-man).