-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 02 Dec 2017 07:34:06 +0100 Source: poppler Binary: libpoppler46 libpoppler-dev libpoppler-private-dev libpoppler-glib8 libpoppler-glib-dev libpoppler-glib-doc gir1.2-poppler-0.18 libpoppler-qt4-4 libpoppler-qt4-dev libpoppler-qt5-1 libpoppler-qt5-dev libpoppler-cpp0 libpoppler-cpp-dev poppler-utils poppler-dbg Architecture: ppc64el Version: 0.26.5-2+deb8u2 Distribution: jessie-security Urgency: medium Maintainer: ppc64el Build Daemon (ppc64el-osuosl-01) Changed-By: Santiago R.R. Description: gir1.2-poppler-0.18 - GObject introspection data for poppler-glib libpoppler-cpp-dev - PDF rendering library -- development files (CPP interface) libpoppler-cpp0 - PDF rendering library (CPP shared library) libpoppler-dev - PDF rendering library -- development files libpoppler-glib-dev - PDF rendering library -- development files (GLib interface) libpoppler-glib-doc - PDF rendering library -- documentation for the GLib interface libpoppler-glib8 - PDF rendering library (GLib-based shared library) libpoppler-private-dev - PDF rendering library -- private development files libpoppler-qt4-4 - PDF rendering library (Qt 4 based shared library) libpoppler-qt4-dev - PDF rendering library -- development files (Qt 4 interface) libpoppler-qt5-1 - PDF rendering library (Qt 5 based shared library) libpoppler-qt5-dev - PDF rendering library -- development files (Qt 5 interface) libpoppler46 - PDF rendering library poppler-dbg - PDF rendering library -- debugging symbols poppler-utils - PDF utilities (based on Poppler) Changes: poppler (0.26.5-2+deb8u2) jessie-security; urgency=medium . * Fix CVE-2017-9406: a memory leak vulnerability was found in the function gmalloc in gmem.cc, which allows attackers to cause a denial of service via a crafted file. * Fix CVE-2017-9408: memory leak in the function Object::initArray in Object.cc that allows attackers to cause a DoS via a crafted file. * Fix CVE-2017-9775: Stack buffer overflow in GfxState.cc in pdftocairo that allows remote attackers to cause a denial of service (application crash) via a crafted PDF document. * Fix CVE-2017-9776: Integer overflow leading to Heap buffer overflow in JBIG2Stream.cc in pdftocairo allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted PDF document. * Fix CVE-2017-9865: The function GfxImageColorMap::getGray in GfxState.cc allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) via a crafted PDF document * Fix CVE-2017-14517: NULL pointer dereference vulnerability in the XRef::parseEntry() function in XRef.cc * Fix CVE-2017-14518: Floating point exception in the isImageInterpolationRequired() function in Splash.cc * Fix CVE-2017-14519: A memory corruption may occur in a call to Object::streamGetChar * Fix CVE-2017-14520: Floating point exception in Splash::scaleImageYuXd() * Fix CVE-2017-14617: Floating point exception in the ImageStream class in Stream.cc * Fix CVE-2017-14975: NULL pointer dereference vulnerability in the FoFiType1C::convertToType0 function in FoFiType1C.cc * Fix CVE-2017-14976: Heap-based buffer over-read vulnerability in the FoFiType1C::convertToType0 function in FoFiType1C.cc * Fix CVE-2017-14977: NULL pointer dereference vulnerability in the FoFiTrueType::getCFFBlock function in FoFiTrueType.cc * Fix CVE-2017-15565: NULL Pointer Dereference in the GfxImageColorMap::getGrayLine() function in GfxState.cc Checksums-Sha1: 7c5489318eaffeb94fd45383588c0916d4496cb7 1157198 libpoppler46_0.26.5-2+deb8u2_ppc64el.deb 4f3a66ea72a378a3e79112704764c060e14f58cb 726162 libpoppler-dev_0.26.5-2+deb8u2_ppc64el.deb 4d126f4bccc4a96d5adaff238aa5b707dcf24e31 179078 libpoppler-private-dev_0.26.5-2+deb8u2_ppc64el.deb 88f5e35905dcc2975af64cc45c57737a8fb9fc9a 110366 libpoppler-glib8_0.26.5-2+deb8u2_ppc64el.deb ecd421398b801e95ae4fe6a462be85dab7491e41 157360 libpoppler-glib-dev_0.26.5-2+deb8u2_ppc64el.deb 3b4d2a1ac12e8876e3e2cb6faea8a59dbc315421 33548 gir1.2-poppler-0.18_0.26.5-2+deb8u2_ppc64el.deb 323f7228bdc889ec32ba63397851bf8c0818e21e 117354 libpoppler-qt4-4_0.26.5-2+deb8u2_ppc64el.deb 5ced96c89b1148db93ac74f726e6e8728466f544 152208 libpoppler-qt4-dev_0.26.5-2+deb8u2_ppc64el.deb 3103a31a51dec0a84c018935ec1bb2be25486884 121114 libpoppler-qt5-1_0.26.5-2+deb8u2_ppc64el.deb c7256bb9ceafd57c6dd518abab6402311b816ecf 157646 libpoppler-qt5-dev_0.26.5-2+deb8u2_ppc64el.deb cdba4aec256102097297944276840cedcff29737 41856 libpoppler-cpp0_0.26.5-2+deb8u2_ppc64el.deb 56e81623a255928d59ae588e0ae38bd23452482a 47436 libpoppler-cpp-dev_0.26.5-2+deb8u2_ppc64el.deb 4c6df8c2ae3485c7bbfc4286bdfe749d5e1b5019 130450 poppler-utils_0.26.5-2+deb8u2_ppc64el.deb 5a1969465de217959390d15e307dd2236d1d663c 7967502 poppler-dbg_0.26.5-2+deb8u2_ppc64el.deb Checksums-Sha256: 348a721693895bd90695786dbc265150039ff2f702aea346823a3bc9da233882 1157198 libpoppler46_0.26.5-2+deb8u2_ppc64el.deb 1e6ef469c59f5b856f962b22413903ab690d36deea16337437fc9e7f146159b1 726162 libpoppler-dev_0.26.5-2+deb8u2_ppc64el.deb 6ee832e4004dfc134f21fadffd58215f38f380f3520e42d212e067500235cf6e 179078 libpoppler-private-dev_0.26.5-2+deb8u2_ppc64el.deb 0c556cf55a6619430d3a56eabec6a595c855f7eee5785a8c5aec027bc837f257 110366 libpoppler-glib8_0.26.5-2+deb8u2_ppc64el.deb 48f89698b70bd92c831536e2deee8bda6ca66337a4a0cd8dbb6e51c130bf6c90 157360 libpoppler-glib-dev_0.26.5-2+deb8u2_ppc64el.deb 6e25856d5c2575f7339be6888ba2cb0590b47cd30d02ae0cbed92ea9170c84ff 33548 gir1.2-poppler-0.18_0.26.5-2+deb8u2_ppc64el.deb 68168ec0721dcfc9114f2d6c03186ffbbe8938a8b7423c45a2863cfa636e22e1 117354 libpoppler-qt4-4_0.26.5-2+deb8u2_ppc64el.deb f42606715e39eaaceb6197daa8fc58527f9a2821295b8f9f50f4a56992f5bbd0 152208 libpoppler-qt4-dev_0.26.5-2+deb8u2_ppc64el.deb 348d9fa3f035211ba8ecb36c5b1bea98ea9b6d39a8d8f6d1d4a6a9eeb416a624 121114 libpoppler-qt5-1_0.26.5-2+deb8u2_ppc64el.deb c3c699dec162a48935ea1bddfb7f2df43492894a156ef3e618658f54f1dc27b1 157646 libpoppler-qt5-dev_0.26.5-2+deb8u2_ppc64el.deb dd6c4601e928df42ae03fdc283d9f21522336d5f7d5e629ebe631e129009a39a 41856 libpoppler-cpp0_0.26.5-2+deb8u2_ppc64el.deb 81ed6c43460868e439ba288c0b4dca33c8fb5e9cf0dde15793c2dca4b9f65efe 47436 libpoppler-cpp-dev_0.26.5-2+deb8u2_ppc64el.deb 1aebc9e7a73ae859c43bb51bde64b5f888c4253024b23f1cceb8da48c4f0731b 130450 poppler-utils_0.26.5-2+deb8u2_ppc64el.deb 1957fde451d3bd31ab29f783ba57ad5c63b38bdd901c904a7130e98dfbc5d823 7967502 poppler-dbg_0.26.5-2+deb8u2_ppc64el.deb Files: c7f2ba8d383c80353fd2cddf134d6a97 1157198 libs optional libpoppler46_0.26.5-2+deb8u2_ppc64el.deb b56abc9959f2ae940545ba4724e834ce 726162 libdevel optional libpoppler-dev_0.26.5-2+deb8u2_ppc64el.deb 87c685c6f3034194c6dc454fb7526bec 179078 libdevel optional libpoppler-private-dev_0.26.5-2+deb8u2_ppc64el.deb 12f581c8c7e1e084990aa4071055644b 110366 libs optional libpoppler-glib8_0.26.5-2+deb8u2_ppc64el.deb 9ed78a82ab7da6d61ae188ca638deb0b 157360 libdevel optional libpoppler-glib-dev_0.26.5-2+deb8u2_ppc64el.deb 2c7c0487f673d3e49016c893b29f2f56 33548 introspection optional gir1.2-poppler-0.18_0.26.5-2+deb8u2_ppc64el.deb b84e0c549d2f9895f1eda9d2449b3049 117354 libs optional libpoppler-qt4-4_0.26.5-2+deb8u2_ppc64el.deb 3c97060d8e65baf470997917202ff690 152208 libdevel optional libpoppler-qt4-dev_0.26.5-2+deb8u2_ppc64el.deb 95d040b79dc209114726cdb551ec5aef 121114 libs optional libpoppler-qt5-1_0.26.5-2+deb8u2_ppc64el.deb 305ea5b37c157ae662894713ac2b8cbe 157646 libdevel optional libpoppler-qt5-dev_0.26.5-2+deb8u2_ppc64el.deb ea528a8f22d341e48b74a97a720ae54d 41856 libs optional libpoppler-cpp0_0.26.5-2+deb8u2_ppc64el.deb d7e36c5d8772321fab700fc611ac81cc 47436 libdevel optional libpoppler-cpp-dev_0.26.5-2+deb8u2_ppc64el.deb d8fd69876f513630516ab9ae10203b3a 130450 utils optional poppler-utils_0.26.5-2+deb8u2_ppc64el.deb d6fc2e5d5d22ffe7ca175131ae7c52f7 7967502 debug extra poppler-dbg_0.26.5-2+deb8u2_ppc64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEbiFq0D2o6nUzEZYnmczybrX3UtIFAlpJJigACgkQmczybrX3 UtJwNRAAg+pTq4QroWbAx8ZEIHY0j3qZsjljEM9ShAgvcGC8Kx44GStC72QekvnO XMjrPrZETBSCrTVYRr/CAkVQMjhhSqa8JclNns7hjfl1+4uAPmGpMMWT7JBmtqfW QRX58Nz7Y+wU3TwIv5uFz8j3/OYqoynN3J3CuTqXW1B+sDHflLJNJhjHAvMdkAEW d4PnPfE/TuiiACFAhXKDXN/N3nix8qBr9/Tv2b2A3zxD/0govFKvHp3v25mEAiT0 nXBFcEsok+VZO0a/bb6LXCaZbL7tnbBRt2Y4LZaH3isEtFYGCLMjysSgCBuw/KY7 jeDrVcexX3ioPSZ68Co1LJaHc0fWWnVVs1cnDugLAuV4EJGZdi+WNFb+ROAJ88dy ue2Tlek7UPrraLWCej8GsDyGF0XZvb6odi+XHnOsAIgidRduWb1FaVN7CurxsZyK x/OGs2CkNtDujIoePpkcLqdzVFm5Qczr4Bd/j33KihWQUaSbcyRtxJGWAZhrD4W/ L8UWo979cyuTiQeJauwbp1NmAJ85AurolmJ0ggfRUo+BDEZfAjqz0/0FmwdtjjQJ HDlk/3oClA72QveHJN+G6zzSG2Qpm+lsTQDqOrqMqItgTZpxdyTqD67dI0nq95SY 3orvAqrgNAd9sIolcvROW3UoH4SJhFfLH+fFQvAGKCTRNscjpqA= =6e2M -----END PGP SIGNATURE-----