SB2013041708 - Buffer overflow in poppler (Alpine package)
Published: April 17, 2013
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Buffer overflow (CVE-ID: CVE-2013-1788)
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
poppler before 0.22.1 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors that trigger an "invalid memory access" in (1) splash/Splash.cc, (2) poppler/Function.cc, and (3) poppler/Stream.cc.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=8d87ec68389b741072a10feef59462edc468349b
- https://git.alpinelinux.org/aports/commit/?id=1598e4619346fb0511d0812de35a5b537a2a0fa8
- https://git.alpinelinux.org/aports/commit/?id=f0d180a0a32dc75f918cee757f7ae1b0a78ec5c2
- https://git.alpinelinux.org/aports/commit/?id=07a8193cc3170444a94248931681eeef831f5579