SB2018010808 - Ubuntu update for poppler
Published: January 8, 2018
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Memory corruption (CVE-ID: CVE-2017-1000456)
The vulnerability allows a remote attacker to cause DoS condition on the target system.The weakness exists due to improper validation of boundaries in TextPool::addWord in freedesktop.org libpoppler. A remote attacker can trigger overflow in subsequent calculations and cause the service to crash.
2) Heap-based buffer overflow (CVE-ID: CVE-2017-14976)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to boundary error in FoFiType1C::convertToType0 function in FoFiType1C.cc when processing fonts in documents. A remote unauthenticated attacker can create a specially crafted document and trigger application crash.
Remediation
Install update from vendor's website.