Bug 1149635 (CVE-2018-21009) - VUL-1: CVE-2018-21009: xpdf,poppler: integer overflow in Parser:makeStream in Parser.cc.
Summary: VUL-1: CVE-2018-21009: xpdf,poppler: integer overflow in Parser:makeStream in...
Status: RESOLVED FIXED
Alias: CVE-2018-21009
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other Other
: P4 - Low : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/241778/
Whiteboard: CVSSv3:SUSE:CVE-2018-21009:4.0:(AV:L/...
Keywords:
Depends on:
Blocks:
 
Reported: 2019-09-05 15:26 UTC by Alexandros Toptsoglou
Modified: 2024-07-26 10:10 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexandros Toptsoglou 2019-09-05 15:26:02 UTC
CVE-2018-21009

Poppler before 0.76.0 has an integer overflow in Parser::makeStream in
Parser.cc.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-21009
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-21009
https://gitlab.freedesktop.org/poppler/poppler/commit/0868c499a9f5f37f8df5c9fef03c37496b40fc8a
Comment 1 Alexandros Toptsoglou 2019-09-05 15:29:02 UTC
Based on the commit fix [1] the version 0.66 is already fixed. Doing some investigation it seems that all the versions of our poppler and xpdf are affected.

I could not locate any POC or further information.

[1] https://gitlab.freedesktop.org/poppler/poppler/commit/0868c499a9f5f37f8df5c9fef03c37496b40fc8a
Comment 2 Petr Gajdos 2023-06-20 18:38:06 UTC
TW,15sp4,15sp2/poppler already fixed, 15,12sp2,12 need the patch.
Comment 4 Maintenance Automation 2023-07-14 21:42:56 UTC
SUSE-SU-2023:2838-1: An update that solves three vulnerabilities can now be installed.

Category: security (moderate)
Bug References: 1136105, 1149635, 1199272
CVE References: CVE-2018-21009, CVE-2019-12293, CVE-2022-27337
Sources used:
openSUSE Leap 15.4 (src): poppler-0.62.0-150000.4.15.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 5 Petr Gajdos 2023-07-18 10:41:20 UTC
I believe all fixed.
Comment 6 Maintenance Automation 2023-07-20 12:30:44 UTC
SUSE-SU-2023:2907-1: An update that solves 14 vulnerabilities can now be installed.

Category: security (moderate)
Bug References: 1092945, 1102531, 1107597, 1114966, 1115185, 1115186, 1115187, 1115626, 1120939, 1124150, 1136105, 1149635, 1199272
CVE References: CVE-2017-18267, CVE-2018-13988, CVE-2018-16646, CVE-2018-18897, CVE-2018-19058, CVE-2018-19059, CVE-2018-19060, CVE-2018-19149, CVE-2018-20481, CVE-2018-20650, CVE-2018-21009, CVE-2019-12293, CVE-2019-7310, CVE-2022-27337
Sources used:
SUSE Linux Enterprise Software Development Kit 12 SP5 (src): poppler-qt-0.43.0-16.25.1, poppler-0.43.0-16.25.1
SUSE Linux Enterprise High Performance Computing 12 SP5 (src): poppler-qt-0.43.0-16.25.1, poppler-0.43.0-16.25.1
SUSE Linux Enterprise Server 12 SP5 (src): poppler-qt-0.43.0-16.25.1, poppler-0.43.0-16.25.1
SUSE Linux Enterprise Server for SAP Applications 12 SP5 (src): poppler-qt-0.43.0-16.25.1, poppler-0.43.0-16.25.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 7 Maintenance Automation 2023-07-20 12:30:49 UTC
SUSE-SU-2023:2906-1: An update that solves 13 vulnerabilities can now be installed.

Category: security (moderate)
Bug References: 1092945, 1102531, 1107597, 1114966, 1115185, 1115186, 1115187, 1115626, 1120939, 1124150, 1149635, 1199272
CVE References: CVE-2017-18267, CVE-2018-13988, CVE-2018-16646, CVE-2018-18897, CVE-2018-19058, CVE-2018-19059, CVE-2018-19060, CVE-2018-19149, CVE-2018-20481, CVE-2018-20650, CVE-2018-21009, CVE-2019-7310, CVE-2022-27337
Sources used:
SUSE Linux Enterprise Software Development Kit 12 SP5 (src): poppler-0.24.4-14.26.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 8 Andrea Mattiazzo 2024-07-26 10:10:18 UTC
All done, closing.