USN-3837-2: poppler regression
11 December 2018
USN-3837-1 introduced a regression in poppler.
Releases
Packages
- poppler - PDF rendering library
Details
USN-3837-1 fixed vulnerabilities in poppler. A regression was reported
regarding the previous update. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that poppler incorrectly handled certain PDF files.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2018-16646)
It was discovered that poppler incorrectly handled certain PDF files.
An attacker could possibly use this issue to cause a denial of service.
This issue only affected Ubuntu 16.04 LTS.
(CVE-2018-19149)
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 18.10
Ubuntu 18.04
Ubuntu 16.04
Ubuntu 14.04
In general, a standard system update will make all the necessary changes.
References
Related notices
- USN-3837-1: libpoppler-private-dev, poppler, libpoppler-glib8, libpoppler-cpp0, libpoppler44, libpoppler-qt5-1, libpoppler-qt5-dev, libpoppler-cpp-dev, libpoppler-qt4-dev, libpoppler-cpp0v5, libpoppler-glib-dev, gir1.2-poppler-0.18, libpoppler-qt4-4, libpoppler58, libpoppler73, libpoppler79, libpoppler-glib-doc, poppler-utils, libpoppler-dev