Package "libpoppler134"
| Name: |
libpoppler134
|
Description: |
PDF rendering library
|
| Latest version: |
24.02.0-1ubuntu9.10 |
| Release: |
noble (24.04) |
| Level: |
security |
| Repository: |
main |
| Head package: |
poppler |
| Homepage: |
https://poppler.freedesktop.org/ |
Links
Download "libpoppler134"
Other versions of "libpoppler134" in Noble
Changelog
|
poppler (24.02.0-1ubuntu9.10) noble-security; urgency=medium
* SECURITY UPDATE: overflow in FoFiTrueType::cvtSfnts
- debian/patches/CVE-2026-102620.patch: Fix integer overflow in
FoFiTrueType::cvtSfnts in fofi/FoFiTrueType.cc.
- CVE-2026-102620
* SECURITY UPDATE: overflow in SplashClip::clipToPath
- debian/patches/CVE-2026-102621.patch: Fix integer overflow in
SplashClip::clipToPath in splash/SplashClip.cc.
- CVE-2026-102621
* SECURITY UPDATE: null pointer deref issue
- debian/patches/CVE-2026-93312.patch: Fix nullptr + number in
poppler/JBIG2Stream.cc.
- CVE-2026-93312
* SECURITY UPDATE: overflow in JBIG2Stream::readCodeTableSeg
- debian/patches/CVE-2026-93313.patch: Fix integer overflow in
JBIG2Stream::readCodeTableSeg in poppler/JBIG2Stream.cc.
- CVE-2026-93313
* SECURITY UPDATE: overflow in FoFiTrueType::mapCodeToGID
- debian/patches/CVE-2026-93314.patch: FoFiTrueType::mapCodeToGID: Improve
b*12 overflow check in fofi/FoFiTrueType.cc.
- CVE-2026-93314
-- Marc Deslauriers Tue, 06 Oct 2026 13:36:43 -0400
|
| Source diff to previous version |
| CVE-2026-102620 |
A vulnerability was determined in Freedesktop Poppler 26.06.0/26.07.0/26.08.0. This impacts the function FoFiTrueType::cvtSfnts of the file fofi/FoFi |
| CVE-2026-102621 |
A vulnerability was identified in Freedesktop Poppler up to 26.08.0. Affected is the function SplashClip::clipToPath of the file splash/SplashClip.cc |
| CVE-2026-93312 |
A flaw has been found in Freedesktop Poppler 26.07.0. Impacted is the function JBIG2Stream::rewind of the file poppler/JBIG2Stream.cc. This manipulat |
| CVE-2026-93313 |
A vulnerability was found in Freedesktop Poppler 26.07.0. The impacted element is the function JBIG2Stream::readCodeTableSeg of the file poppler/JBIG |
| CVE-2026-93314 |
A vulnerability was determined in Freedesktop Poppler 26.07.0. This affects the function FoFiTrueType::mapCodeToGID of the file fofi/FoFiTrueType.cc. |
|
|
poppler (24.02.0-1ubuntu9.9) noble-security; urgency=medium
* SECURITY UPDATE: integer overflow in Splash backend
- debian/patches/CVE-2026-10118.patch: SplashOutputDev: Fix integer overflow
in tilingPatternFill in poppler/SplashOutputDev.cc.
- CVE-2026-10118
-- Marc Deslauriers <email address hidden> Thu, 04 Jun 2026 10:46:44 -0400
|
| Source diff to previous version |
| CVE-2026-10118 |
A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered |
|
|
poppler (24.02.0-1ubuntu9.8) noble-security; urgency=medium
* SECURITY UPDATE: User after free
- debian/patches/CVE-2025-52885.patch: check for duplicate
entries in poppler/StructTreeRoot.cc.
- CVE-2025-52885
-- Leonidas Da Silva Barbosa <email address hidden> Mon, 03 Nov 2025 07:57:48 -0300
|
| Source diff to previous version |
| CVE-2025-52885 |
Poppler ia a library for rendering PDF files, and examining or modifying their structure. A use-after-free (write) vulnerability has been detected in |
|
|
poppler (24.02.0-1ubuntu9.7) noble-security; urgency=medium
* SECURITY UPDATE: stack consumption via metadata
- debian/patches/CVE-2025-43718.patch: make sure regex doesn't stack
overflow by limiting it in poppler/PDFDoc.cc.
- CVE-2025-43718
-- Marc Deslauriers <email address hidden> Fri, 03 Oct 2025 07:36:12 -0400
|
| Source diff to previous version |
| CVE-2025-43718 |
Poppler 24.06.1 through 25.x before 25.04.0 allows stack consumption and a SIGSEGV via deeply nested structures within the metadata (such as GTS_PDFE |
|
|
poppler (24.02.0-1ubuntu9.6) noble-security; urgency=medium
* SECURITY UPDATE: Denial of service
- debian/patches/CVE-2025-50420.patch: don't continue
recursing in PDFDoc in poppler/PDFDoc.cc.
- CVE-2025-50420
-- Leonidas Da Silva Barbosa <email address hidden> Tue, 12 Aug 2025 12:43:49 -0300
|
| CVE-2025-50420 |
An issue in the pdfseparate utility of freedesktop poppler v25.04.0 allows attackers to cause an infinite recursion via supplying a crafted PDF file. |
|
About
-
Send Feedback to @ubuntu_updates