SB2019092111 - Integer overflow in poppler (Alpine package)
Published: September 21, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Integer overflow (CVE-ID: CVE-2019-9959)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to integer overflow in the "JPXStream::init" function, caused by a failure to bounds-check user-supplied data before copying it to an undersized memory buffer. A remote attacker can supply crafted data to the system, trigger integer overflow and cause a denial of service condition on the targeted system.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=3ddd3daf1f05d03d2744a069803a7e5a15275b3a
- https://git.alpinelinux.org/aports/commit/?id=d2eded52b94c3592b8c211f52039156824ab8787
- https://git.alpinelinux.org/aports/commit/?id=fcdf03a54f9c9da28b86742c7745c76c1e110d82
- https://git.alpinelinux.org/aports/commit/?id=40640b4440e2770526a04fbb0eff7c4feb5d7732
- https://git.alpinelinux.org/aports/commit/?id=9f54be14e186e5bf5f2fc23024ddf1a6fb4cc8d3
- https://git.alpinelinux.org/aports/commit/?id=a88d7a223d3ec1b5f5c1719bc91a9b0eb102b3cd
- https://git.alpinelinux.org/aports/commit/?id=14226b276f668d5f0526a7c87e9d0d83b1e8da8e
- https://git.alpinelinux.org/aports/commit/?id=f6c7ae5be78f912c36b8afff560363c1f8404cb0