Bugzilla – Bug 1099720
VUL-0: CVE-2018-12982: podofo: invalid memory read bug in PdfVariant::DelayedLoad()
Last modified: 2019-10-30 16:39:26 UTC
rh#1595689 Invalid memory read in the PoDoFo::PdfVariant::DelayedLoad() function in PdfVariant.h in PoDoFo 0.9.6-rc1 allows remote attackers to have denial-of-service impact via a crafted file. References: https://bugzilla.redhat.com/show_bug.cgi?id=1595689 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-12982
Can you take this Antonio. Thanks.
SUSE-SU-2019:1849-1: An update that fixes 5 vulnerabilities is now available. Category: security (moderate) Bug References: 1035596,1076962,1096890,1099720,1124357 CVE References: CVE-2017-8054,CVE-2018-11255,CVE-2018-12982,CVE-2018-20751,CVE-2018-5783 Sources used: SUSE Linux Enterprise Workstation Extension 12-SP4 (src): podofo-0.9.2-3.9.2 SUSE Linux Enterprise Software Development Kit 12-SP4 (src): podofo-0.9.2-3.9.2 SUSE Linux Enterprise Desktop 12-SP4 (src): podofo-0.9.2-3.9.2 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
leap has podofo 0.9.6 version update, so also fixed.