First published: Tue May 15 2018(Updated: )
It was discovered that poppler incorrectly handled certain PDF files. An attacker could possibly use this to cause a denial of service. (CVE-2017-18267) It was discovered that poppler incorrectly handled certain PDF files. An attacker could possibly use this to cause a denial of service. This issue only affected Ubuntu 14.04 LTS. (CVE-2018-10768)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libpoppler73 | <0.62.0-2ubuntu2.1 | 0.62.0-2ubuntu2.1 |
=18.04 | ||
All of | ||
ubuntu/poppler-utils | <0.62.0-2ubuntu2.1 | 0.62.0-2ubuntu2.1 |
=18.04 | ||
All of | ||
ubuntu/libpoppler68 | <0.57.0-2ubuntu4.3 | 0.57.0-2ubuntu4.3 |
=17.10 | ||
All of | ||
ubuntu/poppler-utils | <0.57.0-2ubuntu4.3 | 0.57.0-2ubuntu4.3 |
=17.10 | ||
All of | ||
ubuntu/libpoppler58 | <0.41.0-0ubuntu1.7 | 0.41.0-0ubuntu1.7 |
=16.04 | ||
All of | ||
ubuntu/poppler-utils | <0.41.0-0ubuntu1.7 | 0.41.0-0ubuntu1.7 |
=16.04 | ||
All of | ||
ubuntu/libpoppler44 | <0.24.5-2ubuntu4.11 | 0.24.5-2ubuntu4.11 |
=14.04 | ||
All of | ||
ubuntu/poppler-utils | <0.24.5-2ubuntu4.11 | 0.24.5-2ubuntu4.11 |
=14.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of USN-3647-1 is medium.
An attacker could exploit USN-3647-1 by using specially crafted PDF files to cause a denial of service.
The following software versions are affected by USN-3647-1: libpoppler73 version 0.62.0-2ubuntu2.1, poppler-utils version 0.62.0-2ubuntu2.1, libpoppler68 version 0.57.0-2ubuntu4.3, poppler-utils version 0.57.0-2ubuntu4.3, libpoppler58 version 0.41.0-0ubuntu1.7, poppler-utils version 0.41.0-0ubuntu1.7, libpoppler44 version 0.24.5-2ubuntu4.11, and poppler-utils version 0.24.5-2ubuntu4.11.
To fix USN-3647-1, you should update the affected software to the following versions: libpoppler73 version 0.62.0-2ubuntu2.1, poppler-utils version 0.62.0-2ubuntu2.1, libpoppler68 version 0.57.0-2ubuntu4.3, poppler-utils version 0.57.0-2ubuntu4.3, libpoppler58 version 0.41.0-0ubuntu1.7, poppler-utils version 0.41.0-0ubuntu1.7, libpoppler44 version 0.24.5-2ubuntu4.11, and poppler-utils version 0.24.5-2ubuntu4.11.
You can find more information about USN-3647-1 at the following references: [link1](https://ubuntu.com/security/CVE-2017-18267) and [link2](https://ubuntu.com/security/CVE-2018-10768).