Bug 1120495 (CVE-2018-20481) - VUL-1: CVE-2018-20481: poppler: XRef::getEntry in XRef.cc mishandles unallocated XRef entries
Summary: VUL-1: CVE-2018-20481: poppler: XRef::getEntry in XRef.cc mishandles unalloca...
Status: RESOLVED FIXED
Alias: CVE-2018-20481
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P4 - Low : Minor
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/221857/
Whiteboard: CVSSv3:SUSE:CVE-2018-20481:3.3:(AV:L/...
Keywords:
Depends on:
Blocks:
 
Reported: 2019-01-02 13:30 UTC by Alexander Bergmann
Modified: 2024-07-25 03:48 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2019-01-02 13:30:09 UTC
CVE-2018-20481

XRef::getEntry in XRef.cc in Poppler 0.72.0 mishandles unallocated XRef entries,
which allows remote attackers to cause a denial of service (NULL pointer
dereference) via a crafted PDF document, when XRefEntry::setFlag in XRef.h is
called from Parser::makeStream in Parser.cc.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-20481
http://people.canonical.com/~ubuntu-security/cve/2018/CVE-2018-20481.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20481
https://gitlab.freedesktop.org/poppler/poppler/issues/692
https://gitlab.freedesktop.org/poppler/poppler/merge_requests/143
Comment 4 Swamp Workflow Management 2021-12-01 20:29:04 UTC
SUSE-SU-2021:3854-1: An update that fixes 21 vulnerabilities is now available.

Category: security (important)
Bug References: 1092945,1102531,1107597,1114966,1115185,1115186,1115187,1115626,1120495,1120496,1120939,1120956,1124150,1127329,1129202,1130229,1131696,1131722,1142465,1143950,1179163
CVE References: CVE-2017-18267,CVE-2018-13988,CVE-2018-16646,CVE-2018-18897,CVE-2018-19058,CVE-2018-19059,CVE-2018-19060,CVE-2018-19149,CVE-2018-20481,CVE-2018-20551,CVE-2018-20650,CVE-2018-20662,CVE-2019-10871,CVE-2019-10872,CVE-2019-14494,CVE-2019-7310,CVE-2019-9200,CVE-2019-9631,CVE-2019-9903,CVE-2019-9959,CVE-2020-27778
JIRA References: 
Sources used:
SUSE Linux Enterprise Workstation Extension 15-SP2 (src):    poppler-0.62.0-4.6.1
SUSE Linux Enterprise Server for SAP 15-SP1 (src):    poppler-0.62.0-4.6.1
SUSE Linux Enterprise Server for SAP 15 (src):    poppler-0.62.0-4.6.1
SUSE Linux Enterprise Server 15-SP1-LTSS (src):    poppler-0.62.0-4.6.1
SUSE Linux Enterprise Server 15-SP1-BCL (src):    poppler-0.62.0-4.6.1
SUSE Linux Enterprise Server 15-LTSS (src):    poppler-0.62.0-4.6.1
SUSE Linux Enterprise High Performance Computing 15-SP1-LTSS (src):    poppler-0.62.0-4.6.1
SUSE Linux Enterprise High Performance Computing 15-SP1-ESPOS (src):    poppler-0.62.0-4.6.1
SUSE Linux Enterprise High Performance Computing 15-LTSS (src):    poppler-0.62.0-4.6.1
SUSE Linux Enterprise High Performance Computing 15-ESPOS (src):    poppler-0.62.0-4.6.1
SUSE Enterprise Storage 6 (src):    poppler-0.62.0-4.6.1
SUSE CaaS Platform 4.0 (src):    poppler-0.62.0-4.6.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 5 Swamp Workflow Management 2021-12-01 21:13:00 UTC
openSUSE-SU-2021:3854-1: An update that fixes 21 vulnerabilities is now available.

Category: security (important)
Bug References: 1092945,1102531,1107597,1114966,1115185,1115186,1115187,1115626,1120495,1120496,1120939,1120956,1124150,1127329,1129202,1130229,1131696,1131722,1142465,1143950,1179163
CVE References: CVE-2017-18267,CVE-2018-13988,CVE-2018-16646,CVE-2018-18897,CVE-2018-19058,CVE-2018-19059,CVE-2018-19060,CVE-2018-19149,CVE-2018-20481,CVE-2018-20551,CVE-2018-20650,CVE-2018-20662,CVE-2019-10871,CVE-2019-10872,CVE-2019-14494,CVE-2019-7310,CVE-2019-9200,CVE-2019-9631,CVE-2019-9903,CVE-2019-9959,CVE-2020-27778
JIRA References: 
Sources used:
openSUSE Leap 15.3 (src):    poppler-0.62.0-4.6.1
Comment 6 Petr Gajdos 2023-06-13 08:02:55 UTC
32-bit arch problem

https://gitlab.freedesktop.org/poppler/poppler/-/commit/39a251b1b3a3343400a08e2f03c5518a26624626

15 fixed, 12 remains.
Comment 7 Petr Gajdos 2023-06-19 12:20:04 UTC
Will submit for 12,12sp2/poppler.
Comment 8 Petr Gajdos 2023-09-22 11:28:19 UTC
Already submitted long time ago.

I believe all fixed.