14 lines
1.1 KiB
JSON
14 lines
1.1 KiB
JSON
{
|
|
"id": "openEuler-SA-2022-1906",
|
|
"url": "https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2022-1906",
|
|
"title": "An update for poppler is now available for openEuler-20.03-LTS-SP1,openEuler-20.03-LTS-SP3 and openEuler-22.03-LTS",
|
|
"severity": "High",
|
|
"description": "Poppler is a free software utility library for rendering Portable Document Format (PDF) documents. \\Its development is supported by freedesktop.org. It is commonly used on Linux systems,and is used by \\the PDF viewers of the open source GNOME and KDE desktop environments.\r\n\r\nSecurity Fix(es):\r\n\r\nPoppler prior to and including 22.08.0 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIGStream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash or the execution of arbitrary code. This is similar to the vulnerability described by CVE-2022-38171 in Xpdf.(CVE-2022-38784)",
|
|
"cves": [
|
|
{
|
|
"id": "CVE-2022-38784",
|
|
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-38784",
|
|
"severity": "High"
|
|
}
|
|
]
|
|
} |