CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:P/I:P/A:P
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
Percentile
89.1%
CentOS Errata and Security Advisory CESA-2019:2022
Poppler is a Portable Document Format (PDF) rendering library, used by applications such as Evince or Okular.
Security Fix(es):
poppler: heap-based buffer over-read in XRef::getEntry in XRef.cc (CVE-2019-7310)
poppler: heap-based buffer overflow in function ImageStream::getLine() in Stream.cc (CVE-2019-9200)
poppler: infinite recursion in Parser::getObj function in Parser.cc (CVE-2018-16646)
poppler: memory leak in GfxColorSpace::setDisplayProfile in GfxState.cc (CVE-2018-18897)
poppler: reachable abort in Object.h (CVE-2018-19058)
poppler: out-of-bounds read in EmbFile::save2 in FileSpec.cc (CVE-2018-19059)
poppler: pdfdetach utility does not validate save paths (CVE-2018-19060)
poppler: NULL pointer dereference in _poppler_attachment_new (CVE-2018-19149)
poppler: NULL pointer dereference in the XRef::getEntry in XRef.cc (CVE-2018-20481)
poppler: reachable Object::dictLookup assertion in FileSpec class in FileSpec.cc (CVE-2018-20650)
poppler: SIGABRT PDFDoc::setup class in PDFDoc.cc (CVE-2018-20662)
poppler: heap-based buffer over-read in function downsample_row_box_filter in CairoRescaleBox.cc (CVE-2019-9631)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Red Hat Enterprise Linux 7.7 Release Notes linked from the References section.
Merged security bulletin from advisories:
https://lists.centos.org/pipermail/centos-cr-announce/2019-August/032130.html
https://lists.centos.org/pipermail/centos-cr-announce/2019-August/032290.html
https://lists.centos.org/pipermail/centos-cr-announce/2019-August/032322.html
Affected packages:
evince
evince-browser-plugin
evince-devel
evince-dvi
evince-libs
evince-nautilus
okular
okular-devel
okular-libs
okular-part
poppler
poppler-cpp
poppler-cpp-devel
poppler-demos
poppler-devel
poppler-glib
poppler-glib-devel
poppler-qt
poppler-qt-devel
poppler-utils
Upstream details at:
https://access.redhat.com/errata/RHSA-2019:2022
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
CentOS | 7 | x86_64 | evince | < 3.28.2-8.el7 | evince-3.28.2-8.el7.x86_64.rpm |
CentOS | 7 | x86_64 | evince-browser-plugin | < 3.28.2-8.el7 | evince-browser-plugin-3.28.2-8.el7.x86_64.rpm |
CentOS | 7 | i686 | evince-devel | < 3.28.2-8.el7 | evince-devel-3.28.2-8.el7.i686.rpm |
CentOS | 7 | x86_64 | evince-devel | < 3.28.2-8.el7 | evince-devel-3.28.2-8.el7.x86_64.rpm |
CentOS | 7 | x86_64 | evince-dvi | < 3.28.2-8.el7 | evince-dvi-3.28.2-8.el7.x86_64.rpm |
CentOS | 7 | i686 | evince-libs | < 3.28.2-8.el7 | evince-libs-3.28.2-8.el7.i686.rpm |
CentOS | 7 | x86_64 | evince-libs | < 3.28.2-8.el7 | evince-libs-3.28.2-8.el7.x86_64.rpm |
CentOS | 7 | x86_64 | evince-nautilus | < 3.28.2-8.el7 | evince-nautilus-3.28.2-8.el7.x86_64.rpm |
CentOS | 7 | x86_64 | okular | < 4.10.5-7.el7 | okular-4.10.5-7.el7.x86_64.rpm |
CentOS | 7 | i686 | okular-devel | < 4.10.5-7.el7 | okular-devel-4.10.5-7.el7.i686.rpm |
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:P/I:P/A:P
CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS
Percentile
89.1%