#16969 closed enhancement (fixed)
poppler-22.09.0
| Reported by: | Bruce Dubbs | Owned by: | Douglas R. Reno |
|---|---|---|---|
| Priority: | high | Milestone: | 11.3 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New monthly version.
Change History (4)
comment:1 by , 4 years ago
| Owner: | changed from to |
|---|---|
| Priority: | normal → high |
| Status: | new → assigned |
comment:2 by , 4 years ago
Release notes:
Release 22.09.0:
core:
* Splash: Do not truncate line dash patterns with more than 20 entries. Issue #1281
* Various signature related improvements
* Fix FormField::getFullyQualifiedName in some scenarios
* Splash: Small optimization on dash pattern handling
* JBIG2Stream::readHalftoneRegionSeg: Fix potential memory leak
* Fix crashes on malformed files. Including CVE-2022-38784
* Fix string formatting in error reporting
utils:
* pdfsig: List signature field names when listing signature information
* pdfsig: Add support for specifying signature by field name
* pdfunite: Fix crashes on malformed files
* pdfunite: Fix potential memory leak of docs
glib:
* Fix two potential memory leaks in poppler_document_create_dests_tree
Information on CVE-2022-38784:
From NVD: Poppler prior to and including 22.08.0 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIGStream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash or the execution of arbitrary code. This is similar to the vulnerability described by CVE-2022-38171 in Xpdf.
Proof of concept is public and can be found at https://github.com/jeffssh/CVE-2021-30860
This is virtually identical to the FORCEDENTRY 0day for Apple devices from last year, which also needed fixes in WebKitGTK+. This will affect every system that has poppler installed.
comment:3 by , 4 years ago
| Resolution: | → fixed |
|---|---|
| Status: | assigned → closed |
comment:4 by , 4 years ago
SA-11.2-001 issued. Made mention of Libreoffice and Inkscape build failures and relevant fixes.

Contains a fix for a variant of the FORCEDENTRY exploit that originally targeted Apple devices. CVE is CVE-2022-38784