Bug#702071: CVE-2013-1788, CVE-2013-1789 and CVE-2013-1790

2013-03-23 Thread Salvatore Bonaccorso
Hi Pino On Mon, Mar 18, 2013 at 05:10:00PM +0100, Salvatore Bonaccorso wrote: > Hi Pino > > On Mon, Mar 18, 2013 at 02:48:18PM +0100, Pino Toscano wrote: > > I've verified the issues, and the situation that I found for current > > wheezy+sid (= 0.18.4-5) is the following: > > > > Alle sabato 2

Bug#702071: CVE-2013-1788, CVE-2013-1789 and CVE-2013-1790

2013-03-18 Thread Salvatore Bonaccorso
Hi Pino On Mon, Mar 18, 2013 at 02:48:18PM +0100, Pino Toscano wrote: > I've verified the issues, and the situation that I found for current > wheezy+sid (= 0.18.4-5) is the following: > > Alle sabato 2 marzo 2013, Salvatore Bonaccorso ha scritto: > > CVE-2013-1788[0]: > > invalid memory issues

Bug#702071: CVE-2013-1788, CVE-2013-1789 and CVE-2013-1790

2013-03-18 Thread Pino Toscano
tag 702071 - moreinfo tag 702071 + confirmed found 702071 poppler/0.18.4-5 thanks Hi, thanks for the tests cases, Salvatore. I've verified the issues, and the situation that I found for current wheezy+sid (= 0.18.4-5) is the following: Alle sabato 2 marzo 2013, Salvatore Bonaccorso ha scritto:

Bug#702071: CVE-2013-1788, CVE-2013-1789 and CVE-2013-1790

2013-03-02 Thread Salvatore Bonaccorso
Ciao Pino Thanks for already working on it! On Sat, Mar 02, 2013 at 06:58:31PM +0100, Pino Toscano wrote: > Would it be possible to have all the test cases references by the CVEs? > (You can email them to me directly, of course.) > Some of the commits mentioned in the Red Hat bugs refer to code

Bug#702071: CVE-2013-1788, CVE-2013-1789 and CVE-2013-1790

2013-03-02 Thread Pino Toscano
Hi, Alle sabato 2 marzo 2013, Salvatore Bonaccorso ha scritto: > the following vulnerabilities were published for poppler. > > CVE-2013-1788[0]: > invalid memory issues > > CVE-2013-1789[1]: > crash in broken documents > > CVE-2013-1790[2]: > uninitialized memory read Ouch... > Patches are re

Bug#702071: CVE-2013-1788, CVE-2013-1789 and CVE-2013-1790

2013-03-02 Thread Salvatore Bonaccorso
Package: poppler Severity: grave Tags: security Hi, the following vulnerabilities were published for poppler. CVE-2013-1788[0]: invalid memory issues CVE-2013-1789[1]: crash in broken documents CVE-2013-1790[2]: uninitialized memory read Patches are referenced in the Red Hat Bugzilla to the r