*** This bug is a security vulnerability ***

You have been subscribed to a public security bug:

System Info: Linux zero 4.15.0-38-generic #41-Ubuntu SMP Wed Oct 10
10:59:38 UTC 2018 x86_64 x86_64 x86_64 GNU/Linux

Evince version: GNOME Document Viewer 3.28.4

While fuzzing evince v3.28.4, on linux 4.15.0-38-generic (Ubuntu 18.04
LTS), a null-pointer dereference was observed, initially this was
reported to evince but the evince team advised that the issue is in
poppler, the library used by evince to render PDF, poppler version:
0.62.0-2ubuntu2.2 is vulnerable to null-pointer dereference, however the
issue is already fixed in poppler 0.70, but this will still crash your
evince v3.28.4 in ubuntu if poppler is not updated to v.0.70.

Fuzzing result showing a very important vulnerability in a package
currently shipped by a major Linux distribution is still of interest,
even if that Linux distribution does not package the latest released
upstream version. I think Ubuntu is still using,

Source: poppler
Version: 0.62.0-2ubuntu2.2

So, most of the systems will be affected to this issue.

Upstream: https://gitlab.freedesktop.org/poppler/poppler/issues/664

** Affects: poppler (Ubuntu)
     Importance: High
         Status: Fix Committed

-- 
Nullpointer dereference
https://bugs.launchpad.net/bugs/1803059
You received this bug notification because you are a member of Ubuntu Touch 
seeded packages, which is subscribed to poppler in Ubuntu.

-- 
Mailing list: https://launchpad.net/~touch-packages
Post to     : touch-packages@lists.launchpad.net
Unsubscribe : https://launchpad.net/~touch-packages
More help   : https://help.launchpad.net/ListHelp

Reply via email to