Bug 845765 (CVE-2010-5110) - VUL-0: CVE-2010-5110: poppler: problem ins DCTStream error handling
Summary: VUL-0: CVE-2010-5110: poppler: problem ins DCTStream error handling
Status: VERIFIED FIXED
Alias: CVE-2010-5110
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL:
Whiteboard: maint:released:sle11-sp1:57500 maint...
Keywords:
Depends on:
Blocks:
 
Reported: 2013-10-14 12:41 UTC by Marcus Meissner
Modified: 2014-06-18 16:37 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2013-10-14 12:41:20 UTC
via oss-sec:

CVE Request : poppler < 0.13.0


Hi,
I'd like to request a CVE number for the following issue
http://cgit.freedesktop.org/poppler/poppler/commit/poppler/DCTStream.cc?id=fc071d800cb4329a3ccf898d7bf16b4db7323ad8

https://bugs.freedesktop.org/show_bug.cgi?id=26280

The bug has been fixed in poppler 0.13.3, back in 2010, though it is
still present and exploitable in several distributions.

Thanks,

Etienne


References:
http://cgit.freedesktop.org/poppler/poppler/commit/poppler/DCTStream.cc?id=fc071d800cb4329a3ccf898d7bf16b4db7323ad8
http://comments.gmane.org/gmane.comp.security.oss.general/11132

https://bugs.freedesktop.org/show_bug.cgi?id=26280
Comment 2 Marcus Meissner 2013-10-16 15:08:13 UTC
I cannot actually evaluate the impact though :/
Comment 3 Swamp Workflow Management 2013-10-16 22:00:08 UTC
bugbot adjusting priority
Comment 4 Petr Tesařík 2014-05-20 11:56:48 UTC
Ooops. Another poppler bug that fell through the cracks.

Re-assigning.
Comment 5 Tomáš Chvátal 2014-05-20 15:28:25 UTC
SLE10SP3 not affected seems.
SLE11SP1 submitted.
Comment 6 Sebastian Krahmer 2014-05-21 06:13:52 UTC
MaintenanceTracker-57494
Comment 10 Swamp Workflow Management 2014-06-18 11:04:23 UTC
Update released for: libpoppler-devel, libpoppler-doc, libpoppler-glib-devel, libpoppler-glib4, libpoppler-qt2, libpoppler-qt3-devel, libpoppler-qt4-3, libpoppler-qt4-devel, libpoppler4, libpoppler5, poppler, poppler-debuginfo, poppler-debugsource, poppler-tools
Products:
SLE-DEBUGINFO 11-SP1-TERADATA (x86_64)
SLE-SERVER 11-SP1-TERADATA (x86_64)
Comment 11 Swamp Workflow Management 2014-06-18 15:50:30 UTC
Update released for: libpoppler-devel, libpoppler-doc, libpoppler-glib-devel, libpoppler-glib4, libpoppler-qt2, libpoppler-qt3-devel, libpoppler-qt4-3, libpoppler-qt4-devel, libpoppler4, libpoppler5, poppler, poppler-debuginfo, poppler-debugsource, poppler-tools
Products:
SLE-DEBUGINFO 11-SP3 (i386, ia64, ppc64, s390x, x86_64)
SLE-DESKTOP 11-SP3 (i386, x86_64)
SLE-SDK 11-SP3 (i386, ia64, ppc64, s390x, x86_64)
SLE-SERVER 11-SP3 (i386, ia64, ppc64, s390x, x86_64)
SLES4VMWARE 11-SP3 (i386, x86_64)
Comment 12 Johannes Segitz 2014-06-18 16:37:04 UTC
all relevant packages were updated