安全公告详情

NS-SA-2026-0109

2026-09-07 18:00:00

简介

important: libppd/xpdf security update

严重级别

important

主题

An update for libppd/xpdf is now available for NewStart CGSL MAIN 7.02.
NewStart Security has rated this update as having a security impact of important. A Common Vunlnerability Scoring System(CVSS)base score, which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.

详细描述

libppd:
xpdf:


Security Fix(es):
libppd: A security vulnerability was found in OpenPrinting CUPS. The function ppdCreatePPDFromIPP2 in the libppd library is responsible for generating a PostScript Printer Description (PPD) file based on attributes retrieved from an Internet Printing Protocol (IPP) response. Essentially, it takes printer information, usually obtained via IPP, and creates a corresponding PPD file that describes the printer's capabilities (such as supported media sizes, resolutions, color modes, etc.). PPD files are used by printing systems like CUPS (Common Unix Printing System) to communicate with and configure printers. They provide a standardized format that allows different printers to work with the printing system in a consistent way. The ppdCreatePPDFromIPP2 function in libppd doesn't properly check or clean IPP attributes before writing them to a temporary PPD file. This means that a remote attacker, who has control of or has hijacked an exposed printer (through UPD or mDNS), could send a harmful IPP attribute and potentially insert malicious commands into the PPD file.(CVE-2024-47175)
libppd: bugfix
xpdf: Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by an invalid VerticesPerRow value in a PDF shading dictionary.(CVE-2025-3154)
xpdf: In Xpdf 4.05 (and earlier), a PDF object loop in a CMap, via the 'UseCMap' entry, leads to infinite recursion and a stack overflow.(CVE-2025-11896)
xpdf: Out-of-bounds array write in Xpdf 4.05 and earlier, due to incorrect integer overflow checking in the PostScript function interpreter code.(CVE-2025-2574)
xpdf: In Xpdf 4.05 (and earlier), very large coordinates in a page box can cause an integer overflow and divide-by-zero.(CVE-2024-7867)
xpdf: In Xpdf 4.05 (and earlier), a PDF object loop in the PDF resources leads to infinite recursion and a stack overflow.(CVE-2024-4568)
xpdf: In Xpdf 4.05 (and earlier), a PDF object loop in an object stream leads to infinite recursion and a stack overflow.(CVE-2024-3247)
xpdf: Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by negative object number in indirect reference in the input PDF file.(CVE-2024-2971)
xpdf: Out-of-bounds array write in Xpdf 4.05 and earlier, due to missing object type check in AcroForm field reference.(CVE-2024-4976)
xpdf: In Xpdf 4.05 (and earlier), invalid header info in a DCT (JPEG) stream can lead to an uninitialized variable in the DCT decoder. The proof-of-concept PDF file causes a segfault attempting to read from an invalid address.(CVE-2024-7868)
xpdf: Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by an invalid character code in a Type 1 font. The root problem was a bounds check that was being optimized away by modern compilers.(CVE-2024-4141)
xpdf: In Xpdf 4.05 (and earlier), a PDF object loop in a pattern resource leads to infinite recursion and a stack overflow.(CVE-2024-7866)
xpdf: Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by long Unicode sequence in ActualText.(CVE-2024-3900)
xpdf: bugfix


Solution:
For details on how to apply this update, which includes the changes described in this advisory, refer to:
http://security.gd-linux.com/how_to_apply_patch.html
Remember the build tag is 7.02.07B5.

影响组件

  • libppd
  • xpdf

影响产品

  • CGSL MAIN 7.02

更新包

{"fix":[{"product":"CGSL MAIN 7.02","pkgs":[{"binary":"","source":""},{"binary":["xpdf-doc-4.06-1.zncgsl7.1.noarch.rpm","xpdf-devel-4.06-1.zncgsl7.1.x86_64.rpm","xpdf-4.06-1.zncgsl7.1.x86_64.rpm"],"source":"xpdf-4.06-1.zncgsl7.1.src.rpm"}]}]}

CVE

参考