SB2013041709 - Buffer overflow in poppler (Alpine package)
Published: April 17, 2013
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Buffer overflow (CVE-ID: CVE-2013-1790)
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
poppler/Stream.cc in poppler before 0.22.1 allows context-dependent attackers to have an unspecified impact via vectors that trigger a read of uninitialized memory by the CCITTFaxStream::lookChar function.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=8d87ec68389b741072a10feef59462edc468349b
- https://git.alpinelinux.org/aports/commit/?id=1598e4619346fb0511d0812de35a5b537a2a0fa8
- https://git.alpinelinux.org/aports/commit/?id=f0d180a0a32dc75f918cee757f7ae1b0a78ec5c2
- https://git.alpinelinux.org/aports/commit/?id=07a8193cc3170444a94248931681eeef831f5579