MGASA-2019-0293

Source
https://advisories.mageia.org/MGASA-2019-0293.html
Import Source
https://advisories.mageia.org/MGASA-2019-0293.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2019-0293
Related
  • CVE-2019-10018
  • CVE-2019-10019
  • CVE-2019-10021
  • CVE-2019-10023
  • CVE-2019-16927
Published
2019-10-06T16:32:38Z
Modified
2019-10-06T16:03:04Z
Summary
Updated xpdf packages fix security vulnerabilities
Details

The updated xpdf packages fix security vulnerabilities:

An issue was discovered in Xpdf 4.01.01. There is an FPE in the function PostScriptFunction::exec at Function.cc for the psOpIdiv case. (CVE-2019-10018)

An issue was discovered in Xpdf 4.01.01. There is an FPE in the function PSOutputDev::checkPageSlice at PSOutputDev.cc for nStripes. (CVE-2019-10019)

An issue was discovered in Xpdf 4.01.01. There is an FPE in the function ImageStream::ImageStream at Stream.cc for nComps. (CVE-2019-10021)

An issue was discovered in Xpdf 4.01.01. There is an FPE in the function PostScriptFunction::exec at Function.cc for the psOpMod case. (CVE-2019-10023)

Xpdf 4.01.01 has an out-of-bounds write in the vertProfile part of the TextPage::findGaps function in TextOutputDev.cc, a different vulnerability than CVE-2019-9877. (CVE-2019-16927)

References
Credits

Affected packages

Mageia:7 / xpdf

Package

Name
xpdf
Purl
pkg:rpm/mageia/xpdf?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.02-1.mga7

Ecosystem specific

{
    "section": "core"
}