Bug#729064: poppler: CVE-2013-4473 CVE-2013-4474

2013-11-17 Thread Pino Toscano
Hi, sorry for the late reply, relocating can take your time. In data venerdì 8 novembre 2013 14:32:24, hai scritto: Two security issues were found in the pdfseparate tool shipped by poppler-utils: Luckly both of them are minor issues, that can be triggered just running pdfseparate. None of

Bug#729064: [Secure-testing-team] Bug#729064: poppler: CVE-2013-4473 CVE-2013-4474

2013-11-17 Thread Pino Toscano
Hi, In data martedì 12 novembre 2013 23:47:21, hai scritto: On Fri, Nov 8, 2013 at 8:32 AM, Moritz Muehlenhoff wrote: Two security issues were found in the pdfseparate tool shipped by poppler-utils: Hi, I've uploaded an nmu fixing these two issue to delayed/5. Please see attached patch.

Bug#729064: [Secure-testing-team] Bug#729064: poppler: CVE-2013-4473 CVE-2013-4474

2013-11-17 Thread Michael Gilbert
On Sun, Nov 17, 2013 at 1:31 PM, Pino Toscano wrote: Unfortunately, one of your patches introduces the same issues it is supposed to fix: +@@ -65,9 +66,37 @@ + if (firstPage == 0) + firstPage = 1; + if (firstPage != lastPage strstr(destFileName, %d) == NULL) { +-error(-1, '%s'

Bug#729064: poppler: CVE-2013-4473 CVE-2013-4474

2013-11-17 Thread Moritz Muehlenhoff
On Sun, Nov 17, 2013 at 07:30:17PM +0100, Pino Toscano wrote: Hi, sorry for the late reply, relocating can take your time. In data venerdì 8 novembre 2013 14:32:24, hai scritto: Two security issues were found in the pdfseparate tool shipped by poppler-utils: Luckly both of them are

Bug#729064: [Secure-testing-team] Bug#729064: poppler: CVE-2013-4473 CVE-2013-4474

2013-11-12 Thread Michael Gilbert
control: tag -1 patch control: tag -1 pending On Fri, Nov 8, 2013 at 8:32 AM, Moritz Muehlenhoff wrote: Two security issues were found in the pdfseparate tool shipped by poppler-utils: Hi, I've uploaded an nmu fixing these two issue to delayed/5. Please see attached patch. Best wishes, Mike

Bug#729064: poppler: CVE-2013-4473 CVE-2013-4474

2013-11-08 Thread Moritz Muehlenhoff
Package: poppler Severity: important Tags: security Two security issues were found in the pdfseparate tool shipped by poppler-utils: CVE-2013-4473: buffer overflow http://cgit.freedesktop.org/poppler/poppler/diff/utils/pdfseparate.cc?id=b8682d868ddf7f741e93b CVE-2013-4474: format string issue