ALT-BU-2021-3717-3
Branch sisyphus update bulletin.
Closed vulnerabilities
BDU:2023-07872
Уязвимость функции Catalog::findDestInTree() программного обеспечения для просмотра PDF Xpdf, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2020-25725
In Xpdf 4.02, SplashOutputDev::endType3Char(GfxState *state) SplashOutputDev.cc:3079 is trying to use the freed `t3GlyphStack->cache`, which causes an `heap-use-after-free` problem. The codes of a previous fix for nested Type 3 characters wasn't correctly handling the case where a Type 3 char referred to another char in the same Type 3 font.
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-25725
- https://forum.xpdfreader.com/viewtopic.php?f=3&t=41915
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4ZUU5QG6SSVRTKZTR3A72LDRVZETEI63/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VLOYVJSM54IL6I5RY4QTJGRS7PIEG44X/
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-25725
- https://forum.xpdfreader.com/viewtopic.php?f=3&t=41915
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4ZUU5QG6SSVRTKZTR3A72LDRVZETEI63/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VLOYVJSM54IL6I5RY4QTJGRS7PIEG44X/
Modified: 2024-11-21
CVE-2020-35376
Xpdf 4.02 allows stack consumption because of an incorrect subroutine reference in a Type 1C font charstring, related to the FoFiType1C::getOp() function.
- https://forum.xpdfreader.com/viewtopic.php?f=3&t=42066
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4ZUU5QG6SSVRTKZTR3A72LDRVZETEI63/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VLOYVJSM54IL6I5RY4QTJGRS7PIEG44X/
- https://forum.xpdfreader.com/viewtopic.php?f=3&t=42066
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4ZUU5QG6SSVRTKZTR3A72LDRVZETEI63/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VLOYVJSM54IL6I5RY4QTJGRS7PIEG44X/
Modified: 2024-11-21
CVE-2022-48545
An infinite recursion in Catalog::findDestInTree can cause denial of service for xpdf 4.02.
Package kernel-source-lkrg updated to version 0.8.1+git20210130-alt1 for branch sisyphus in task 265521.
Closed bugs
5.10.11-un-def-alt1 cannot be booted with p_lkrg module
