Mageia Bugzilla – Attachment 9730 Details for
Bug 21825
poppler several new security issues
Home
|
New
|
Browse
|
Search
|
[?]
|
Reports
|
Requests
|
Help
|
Log In
[x]
|
New Account
|
Forgot Password
POC tests before updating
before.pocs (text/plain), 2.07 KB, created by
Len Lawrence
on 2017-10-13 20:57:37 CEST
(
hide
)
Description:
POC tests before updating
Filename:
MIME Type:
Creator:
Len Lawrence
Created:
2017-10-13 20:57:37 CEST
Size:
2.07 KB
patch
obsolete
>Some of the following tests generated files in the test directory... > >CVE-2017-14518 >https://bugs.freedesktop.org/show_bug.cgi?id=102688 >$ pdftohtml -q -s mal-Splash-cc-4141-4-SIGFPE.pdf a >$ > >CVE-2017-14617 >https://bugs.freedesktop.org/show_bug.cgi?id=102854 >$ pdftohtml -q -s mal-Stream-cc-457-4-47.pdf /dev/null >Floating point exception > >CVE-2017-14926 >https://bugs.freedesktop.org/show_bug.cgi?id=102601 >$ pdfinfo ./mal-annot-cc-6577-2-07.pdf >Tagged: no >UserProperties: no >Suspects: no >Form: none >JavaScript: no >Pages: 1 >Encrypted: no >Page size: 612 x 792 pts (letter) >Page rot: 0 >File size: 2666 bytes >Optimized: no >PDF version: 0.0 > >CVE-2017-14928 >https://bugs.freedesktop.org/show_bug.cgi?id=102607 >$ pdftohtml -s ./mal-Annot-cc-6770-3-16.pdf a >Syntax Error: End of file inside dictionary >Syntax Warning: No valid XRef size in trailer >Page-1 > >CVE-2017-14929 >https://bugs.freedesktop.org/show_bug.cgi?id=102969 >No instructions available so pdfinfo was used. >$ pdfinfo mal-gfx-infinite-loop.pdf >Syntax Error (35): Dictionary key must be a name object >Syntax Error (2804): Illegal character <10> in hex string >Tagged: no >UserProperties: no >Suspects: no >Form: none >JavaScript: no >Pages: 1 >Encrypted: no >Page size: 595 x 842 pts (A4) >Page rot: 0 >File size: 2856 bytes >Optimized: no >PDF version: 0.0 > >CVE-2017-14975 >https://bugzilla.freedesktop.org/show_bug.cgi?id=102653 >$ pdftops crash.pdf crash.ps >Segmentation fault > >CVE-2017-14977 >https://bugs.freedesktop.org/show_bug.cgi?id=103045 >$ pdftops -level3 -origpagesizes -form -opi -binary -expand -duplex null3.pdf 1.ps >Syntax Error (220541): Dictionary key must be a name object >Syntax Error (220544): Dictionary key must be a name object >Syntax Error (220544): Illegal character '}' >......................................... >Syntax Error (220563): Dictionary key must be a name object >Syntax Error: Embedded font file may be invalid >Syntax Error: Invalid XRef entry >Syntax Error: Embedded font file is not a stream >Segmentation fault >
Some of the following tests generated files in the test directory... CVE-2017-14518 https://bugs.freedesktop.org/show_bug.cgi?id=102688 $ pdftohtml -q -s mal-Splash-cc-4141-4-SIGFPE.pdf a $ CVE-2017-14617 https://bugs.freedesktop.org/show_bug.cgi?id=102854 $ pdftohtml -q -s mal-Stream-cc-457-4-47.pdf /dev/null Floating point exception CVE-2017-14926 https://bugs.freedesktop.org/show_bug.cgi?id=102601 $ pdfinfo ./mal-annot-cc-6577-2-07.pdf Tagged: no UserProperties: no Suspects: no Form: none JavaScript: no Pages: 1 Encrypted: no Page size: 612 x 792 pts (letter) Page rot: 0 File size: 2666 bytes Optimized: no PDF version: 0.0 CVE-2017-14928 https://bugs.freedesktop.org/show_bug.cgi?id=102607 $ pdftohtml -s ./mal-Annot-cc-6770-3-16.pdf a Syntax Error: End of file inside dictionary Syntax Warning: No valid XRef size in trailer Page-1 CVE-2017-14929 https://bugs.freedesktop.org/show_bug.cgi?id=102969 No instructions available so pdfinfo was used. $ pdfinfo mal-gfx-infinite-loop.pdf Syntax Error (35): Dictionary key must be a name object Syntax Error (2804): Illegal character <10> in hex string Tagged: no UserProperties: no Suspects: no Form: none JavaScript: no Pages: 1 Encrypted: no Page size: 595 x 842 pts (A4) Page rot: 0 File size: 2856 bytes Optimized: no PDF version: 0.0 CVE-2017-14975 https://bugzilla.freedesktop.org/show_bug.cgi?id=102653 $ pdftops crash.pdf crash.ps Segmentation fault CVE-2017-14977 https://bugs.freedesktop.org/show_bug.cgi?id=103045 $ pdftops -level3 -origpagesizes -form -opi -binary -expand -duplex null3.pdf 1.ps Syntax Error (220541): Dictionary key must be a name object Syntax Error (220544): Dictionary key must be a name object Syntax Error (220544): Illegal character '}' ......................................... Syntax Error (220563): Dictionary key must be a name object Syntax Error: Embedded font file may be invalid Syntax Error: Invalid XRef entry Syntax Error: Embedded font file is not a stream Segmentation fault
View Attachment As Raw
Actions:
View
Attachments on
bug 21825
: 9730