安全公告详情

NS-SA-2022-0086

2022-11-09 12:33:35

简介

moderate: evince/file security update

严重级别

moderate

主题

An update for evince/file is now available for NewStart CGSL MAIN 6.02.
NewStart Security has rated this update as having a security impact of moderate. A Common Vunlnerability Scoring System(CVSS)base score, which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.

详细描述

evince: Evince is simple multi-page document viewer. It can display and print Portable Document Format (PDF), PostScript (PS) and Encapsulated PostScript (EPS) files. When supported by the document format, evince allows searching for text, copying text to the clipboard, hypertext navigation, table-of-contents bookmarks and editing of forms.
file: Libraries for applications using libmagic.


Security Fix(es):
evince: A flaw was found in Poppler in the way certain PDF files were converted into HTML. This flaw allows a remote attacker to provide a malicious PDF file that, when processed by the 'pdftohtml' program, crashes the application, causing a denial of service. The highest threat from this vulnerability is to system availability.(CVE-2020-27778)
evince: bugfix
file: cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (4-byte out-of-bounds write).(CVE-2019-18218)
file: bugfix


Solution:
For details on how to apply this update, which includes the changes described in this advisory, refer to:
http://security.gd-linux.com/how_to_apply_patch.html
Remember the build tag is 6.02.B0B9.

影响组件

  • evince
  • file

影响产品

  • CGSL MAIN 6.02

更新包

{"fix":[{"product":"CGSL MAIN 6.02","pkgs":[{"binary":["evince-3.28.4-14.el8.x86_64.rpm","evince-libs-3.28.4-14.el8.x86_64.rpm","evince-nautilus-3.28.4-14.el8.x86_64.rpm"],"source":"evince-3.28.4-14.el8.src.rpm"},{"binary":["file-5.33-20.el8.x86_64.rpm","file-libs-5.33-20.el8.x86_64.rpm","python3-magic-5.33-20.el8.noarch.rpm"],"source":"file-5.33-20.el8.src.rpm"}]}]}

CVE

参考