{"id":"SUSE-SU-2024:3541-1","summary":"Security update for podofo","details":"This update for podofo fixes the following issues:\n\n - CVE-2015-8981: Fixed heap overflow in the function ReadXRefSubsection (bsc#1023190)\n - CVE-2017-6840: Fixed invalid memory read in ColorChanger::GetColorFromStack (colorchanger.cpp) (bsc#1027787)\n - CVE-2017-6841: Fixed NULL pointer dereference in GraphicsStack::TGraphicsStackElement::~TGraphicsStackElement (graphicsstack.h) (bsc#1027786)\n - CVE-2017-6842: Fixed NULL pointer dereference in ColorChanger::GetColorFromStack (colorchanger.cpp) (bsc#1027785)\n - CVE-2017-6845: Fixed NULL pointer dereference in GraphicsStack::TGraphicsStackElement::SetNonStrokingColorSpace (graphicsstack.h) (bsc#1027779)\n - CVE-2017-6849: Fixed NULL pointer dereference in PoDoFo::PdfColorGray::~PdfColorGray (PdfColor.cpp) (bsc#1027776)\n - CVE-2017-8378: Fixed denial of service (application crash) vectors related to m_offsets.size (PdfParser::ReadObjects func in base/PdfParser.cpp) (bsc#1037000)  \n - CVE-2018-5308: Fixed Undefined behavior  (memcpy with NULL pointer) in PdfMemoryOutputStream::Write (src/base/PdfOutputStream.cpp) (bsc#1075772)\n - CVE-2019-10723: Fixed Memory leak in PdfPagesTreeCache class in doc/PdfPagesTreeCache.cpp (bsc#1131544)\n - CVE-2019-9199: Fixed NULL pointer dereference in function PoDoFo:Impose:PdfTranslator:setSource() in pdftranslator.cpp (bsc#1127855)\n\n - Fixed NULL pointer dereference in PdfInfo::GuessFormat (pdfinfo.cpp) (bsc#1023072)\n","modified":"2026-02-04T03:22:38.825984Z","published":"2024-10-08T08:33:37Z","related":["CVE-2015-8981","CVE-2017-5854","CVE-2017-6840","CVE-2017-6841","CVE-2017-6842","CVE-2017-6845","CVE-2017-6849","CVE-2017-8378","CVE-2018-5308","CVE-2019-10723","CVE-2019-9199"],"upstream":["CVE-2015-8981","CVE-2017-5854","CVE-2017-6840","CVE-2017-6841","CVE-2017-6842","CVE-2017-6845","CVE-2017-6849","CVE-2017-8378","CVE-2018-5308","CVE-2019-10723","CVE-2019-9199"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2024/suse-su-20243541-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1023072"},{"type":"REPORT","url":"https://bugzilla.suse.com/1023190"},{"type":"REPORT","url":"https://bugzilla.suse.com/1027776"},{"type":"REPORT","url":"https://bugzilla.suse.com/1027779"},{"type":"REPORT","url":"https://bugzilla.suse.com/1027785"},{"type":"REPORT","url":"https://bugzilla.suse.com/1027786"},{"type":"REPORT","url":"https://bugzilla.suse.com/1027787"},{"type":"REPORT","url":"https://bugzilla.suse.com/1037000"},{"type":"REPORT","url":"https://bugzilla.suse.com/1075772"},{"type":"REPORT","url":"https://bugzilla.suse.com/1127855"},{"type":"REPORT","url":"https://bugzilla.suse.com/1131544"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-8981"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-5854"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-6840"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-6841"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-6842"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-6845"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-6849"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2017-8378"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-5308"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-10723"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-9199"}],"affected":[{"package":{"name":"podofo","ecosystem":"SUSE:Linux Enterprise Software Development Kit 12 SP5","purl":"pkg:rpm/suse/podofo&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.9.2-3.21.1"}]}],"ecosystem_specific":{"binaries":[{"libpodofo-devel":"0.9.2-3.21.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:3541-1.json"}},{"package":{"name":"podofo","ecosystem":"SUSE:Linux Enterprise Workstation Extension 12 SP5","purl":"pkg:rpm/suse/podofo&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.9.2-3.21.1"}]}],"ecosystem_specific":{"binaries":[{"libpodofo0_9_2":"0.9.2-3.21.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2024:3541-1.json"}}],"schema_version":"1.7.3"}