Description
Multiple "input validation flaws" in the JBIG2 decoder in Xpdf 3.02pl2 and
earlier, CUPS 1.3.9 and earlier, Poppler before 0.10.6, and other products
allow remote attackers to execute arbitrary code via a crafted PDF file.
Notes
| jdstrand | CUPS on Ubuntu uses system pdftops (compiled with --disable-pdftops) |
| sbeattie | ipe uses system pdflatex |
Package
Priority: Negligible
Patches:
Package
Priority: Negligible
| Upstream: | released
(1.3.10)
|
| Ubuntu 18.04 LTS: | DNE
|
| Ubuntu 20.04 LTS: | DNE
|
| Ubuntu 21.10: | DNE
|
| Ubuntu 22.04 LTS: | DNE
|
| Ubuntu 14.04 ESM: | DNE
|
Patches:
Package
| Upstream: | not-affected
(linked to poppler)
|
| Ubuntu 18.04 LTS: | not-affected
(linked to poppler)
|
| Ubuntu 20.04 LTS: | not-affected
(linked to poppler)
|
| Ubuntu 21.10: | not-affected
(linked to poppler)
|
| Ubuntu 16.04 ESM: | not-affected
(linked to poppler)
|
| Ubuntu 22.04 LTS: | not-affected
(linked to poppler)
|
| Ubuntu 14.04 ESM: | DNE
(trusty was not-affected [linked to poppler])
|
Patches:
Package
| Upstream: | needs-triage
|
| Ubuntu 18.04 LTS: | DNE
|
| Ubuntu 20.04 LTS: | DNE
|
| Ubuntu 21.10: | DNE
|
| Ubuntu 22.04 LTS: | DNE
|
| Ubuntu 14.04 ESM: | DNE
|
Patches:
Package
| Upstream: | needs-triage
|
| Ubuntu 18.04 LTS: | DNE
|
| Ubuntu 20.04 LTS: | DNE
|
| Ubuntu 21.10: | DNE
|
| Ubuntu 22.04 LTS: | DNE
|
| Ubuntu 14.04 ESM: | DNE
|
Patches:
Package
Priority: Low
| Upstream: | needs-triage
|
| Ubuntu 18.04 LTS: | DNE
|
| Ubuntu 20.04 LTS: | DNE
|
| Ubuntu 21.10: | DNE
|
| Ubuntu 22.04 LTS: | DNE
|
| Ubuntu 14.04 ESM: | DNE
|
Patches:
Package
| Upstream: | needs-triage
|
| Ubuntu 18.04 LTS: | DNE
|
| Ubuntu 20.04 LTS: | DNE
|
| Ubuntu 21.10: | DNE
|
| Ubuntu 22.04 LTS: | DNE
|
| Ubuntu 14.04 ESM: | DNE
|
Patches:
Package
| Upstream: | needs-triage
|
| Ubuntu 18.04 LTS: | DNE
|
| Ubuntu 20.04 LTS: | DNE
|
| Ubuntu 21.10: | DNE
|
| Ubuntu 22.04 LTS: | DNE
|
| Ubuntu 14.04 ESM: | DNE
|
Patches:
Package
| Upstream: | needs-triage
|
| Ubuntu 18.04 LTS: | DNE
|
| Ubuntu 20.04 LTS: | DNE
|
| Ubuntu 21.10: | DNE
|
| Ubuntu 22.04 LTS: | DNE
|
| Ubuntu 14.04 ESM: | DNE
|
Patches:
Package
| Upstream: | needs-triage
|
| Ubuntu 18.04 LTS: | not-affected
(linked to poppler)
|
| Ubuntu 20.04 LTS: | not-affected
(linked to poppler)
|
| Ubuntu 21.10: | not-affected
(linked to poppler)
|
| Ubuntu 16.04 ESM: | not-affected
(linked to poppler)
|
| Ubuntu 22.04 LTS: | not-affected
(linked to poppler)
|
| Ubuntu 14.04 ESM: | DNE
(trusty was not-affected [linked to poppler])
|
Patches:
Updated: 2022-04-25 00:14:21 UTC (commit ecc1009cb19540b950de59270950018900f37f15)