Release date:
2026-08-22 10:56:56 UTC
Description:
* SECURITY UPDATE: crash in pdfinfo -dests on broken documents:
printDestinations() wrapped the destination name returned by
Catalog::getDestNameTreeName() / Catalog::getDestsName() into a new
GooString before testing it, so a document whose name tree is short or
whose /Dests entry is not a dictionary made both getters return NULL and
the GooString constructor dereference it, crashing pdfinfo.
- debian/patches/CVE-2024-6239.patch: read the raw name pointer first and
only build the GooString once name, dest and dest->isPageRef() have all
been checked, in utils/pdfinfo.cc; matches upstream commit 0554731.
- CVE-2024-6239
Updated packages:
-
gir1.2-poppler-0.18_0.62.0-2ubuntu2.14+tuxcare.els1_amd64.deb
sha:e0438897bd3579657418bc40fec742a0f38809cc
-
libpoppler-cpp-dev_0.62.0-2ubuntu2.14+tuxcare.els1_amd64.deb
sha:10d50b845236fe441ccb2dd1fd4e36b2aebc5174
-
libpoppler-cpp0v5_0.62.0-2ubuntu2.14+tuxcare.els1_amd64.deb
sha:8ca1529107c8f9eb12c04b7a38c5c63fad25d4cf
-
libpoppler-dev_0.62.0-2ubuntu2.14+tuxcare.els1_amd64.deb
sha:b6483f144de86e29265e99a980262a82a4782b46
-
libpoppler-glib-dev_0.62.0-2ubuntu2.14+tuxcare.els1_amd64.deb
sha:3c6a605ff21febaecfdb3cdd3ed1edc9faf74a4e
-
libpoppler-glib-doc_0.62.0-2ubuntu2.14+tuxcare.els1_all.deb
sha:b0f12273b9f4bcbde8109b484c2cd91ef215b46c
-
libpoppler-glib8_0.62.0-2ubuntu2.14+tuxcare.els1_amd64.deb
sha:942b17d34dc20deadc212b08004c268a31eed206
-
libpoppler-private-dev_0.62.0-2ubuntu2.14+tuxcare.els1_amd64.deb
sha:56382c32e24ea91add461c3cc82b644840a48e8e
-
libpoppler-qt5-1_0.62.0-2ubuntu2.14+tuxcare.els1_amd64.deb
sha:d4fe6f8e85a13aa356f6e370f6c112d995d669d2
-
libpoppler-qt5-dev_0.62.0-2ubuntu2.14+tuxcare.els1_amd64.deb
sha:a098475bc031de1cc678ed5070474af02d2a6fbc
-
libpoppler73_0.62.0-2ubuntu2.14+tuxcare.els1_amd64.deb
sha:6a7e3a6a788812c4c8663e972832a15e63688415
-
poppler-utils_0.62.0-2ubuntu2.14+tuxcare.els1_amd64.deb
sha:88d889312839d84d22b4138f3e461acbb9decb54
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.