[Buildroot] [PATCH 1/1] package/poppler: security bump to version 22.10.0

Peter Korsgaard peter at korsgaard.com
Wed Oct 26 08:54:20 UTC 2022


>>>>> "Fabrice" == Fabrice Fontaine <fontaine.fabrice at gmail.com> writes:

 > - Fix CVE-2022-38784: Poppler prior to and including 22.08.0 contains an
 >   integer overflow in the JBIG2 decoder
 >   (JBIG2Stream::readTextRegionSeg() in JBIGStream.cc). Processing a
 >   specially crafted PDF file or JBIG2 image could lead to a crash or the
 >   execution of arbitrary code. This is similar to the vulnerability
 >   described by CVE-2022-38171 in Xpdf.
 > - Drop patch (already in version)

 > https://gitlab.freedesktop.org/poppler/poppler/-/blob/poppler-22.10.0/NEWS

 > Signed-off-by: Fabrice Fontaine <fontaine.fabrice at gmail.com>

Committed, thanks.

-- 
Bye, Peter Korsgaard



More information about the buildroot mailing list