ALAS-2020-1398


Amazon Linux 1 Security Advisory: ALAS-2020-1398
Advisory Release Date: 2020-07-14 02:14 Pacific
Advisory Updated Date: 2020-07-15 17:28 Pacific
Severity: Medium

Issue Overview:

The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3.32.0 did not handle errors from TIFFReadRGBAImageOriented(), leading to uninitialized memory use when processing certain TIFF image files. (CVE-2019-11459)

Poppler before 0.66.0 has an integer overflow in Parser::makeStream in Parser.cc. (CVE-2018-21009)

The JPXStream::init function in Poppler 0.78.0 and earlier doesn't check for negative values of stream length, leading to an Integer Overflow, thereby making it possible to allocate a large memory chunk on the heap, with a size controlled by an attacker, as demonstrated by pdftocairo. (CVE-2019-9959)

An issue was discovered in Poppler 0.74.0. There is a heap-based buffer over-read in the function PSOutputDev::checkPageSlice at PSOutputDev.cc. (CVE-2019-10871)

In Poppler through 0.76.1, there is a heap-based buffer over-read in JPXStream::init in JPEG2000Stream.cc via data with inconsistent heights or widths. (CVE-2019-12293)


Affected Packages:

poppler


Issue Correction:
Run yum update poppler to update your system.

New Packages:
i686:
    poppler-devel-0.26.5-42.20.amzn1.i686
    poppler-debuginfo-0.26.5-42.20.amzn1.i686
    poppler-utils-0.26.5-42.20.amzn1.i686
    poppler-glib-0.26.5-42.20.amzn1.i686
    poppler-0.26.5-42.20.amzn1.i686
    poppler-cpp-devel-0.26.5-42.20.amzn1.i686
    poppler-glib-devel-0.26.5-42.20.amzn1.i686
    poppler-cpp-0.26.5-42.20.amzn1.i686

src:
    poppler-0.26.5-42.20.amzn1.src

x86_64:
    poppler-utils-0.26.5-42.20.amzn1.x86_64
    poppler-debuginfo-0.26.5-42.20.amzn1.x86_64
    poppler-glib-devel-0.26.5-42.20.amzn1.x86_64
    poppler-cpp-devel-0.26.5-42.20.amzn1.x86_64
    poppler-glib-0.26.5-42.20.amzn1.x86_64
    poppler-devel-0.26.5-42.20.amzn1.x86_64
    poppler-0.26.5-42.20.amzn1.x86_64
    poppler-cpp-0.26.5-42.20.amzn1.x86_64