Bug 25973 - xpdf new security issue CVE-2019-17064
Summary: xpdf new security issue CVE-2019-17064
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal major
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA7-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2019-12-27 05:10 CET by David Walser
Modified: 2019-12-31 17:52 CET (History)
5 users (show)

See Also:
Source RPM: xpdf-4.02-1.mga7.src.rpm
CVE: CVE-2019-17064
Status comment:


Attachments

Description David Walser 2019-12-27 05:10:16 CET
Fedora has issued an advisory on December 10:
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/TMDB2CGUYDW2RENE2I2TT6QNFEEI2CNF/

Mageia 7 is also affected.
David Walser 2019-12-27 05:10:33 CET

Whiteboard: (none) => MGA7TOO
CC: (none) => nicolas.salguero

Comment 1 Lewis Smith 2019-12-27 11:11:13 CET
Assigning to Nicolas as the recent active maintainer; no registered person.

Assignee: bugsquad => nicolas.salguero

Comment 2 Nicolas Salguero 2019-12-27 11:44:55 CET
Suggested advisory:
========================

The updated packages fix a security vulnerability:

Catalog.cc in Xpdf 4.02 has a NULL pointer dereference because Catalog.pageLabels is initialized too late in the Catalog constructor. (CVE-2019-17064)

References:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17064
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/TMDB2CGUYDW2RENE2I2TT6QNFEEI2CNF/
========================

Updated packages in core/updates_testing:
========================
xpdf-4.02-1.1.mga7
xpdf-common-4.02-1.1.mga7

from SRPMS:
xpdf-4.02-1.1.mga7.src.rpm

Assignee: nicolas.salguero => qa-bugs
CVE: (none) => CVE-2019-17064
Status: NEW => ASSIGNED
Whiteboard: MGA7TOO => (none)
Version: Cauldron => 7

Comment 3 Brian Rockwell 2019-12-27 16:57:03 CET
$ uname -a
Linux localhost.localdomain 5.4.6-desktop-2.mga7 #1 SMP Mon Dec 23 12:05:27 UTC 2019 x86_64 x86_64 x86_64 GNU/Linux

The following 9 packages are going to be installed:

- lib64qt5printsupport5-5.12.6-1.mga7.x86_64
- lib64rpm8-4.14.2.1-13.mga7.x86_64
- python3-rpm-4.14.2.1-13.mga7.x86_64
- rpm-4.14.2.1-13.mga7.x86_64
- rpm-plugin-syslog-4.14.2.1-13.mga7.x86_64
- rpm-plugin-systemd-inhibit-4.14.2.1-13.mga7.x86_64
- x11-font-adobe-100dpi-1.0.3-7.mga7.noarch
- xpdf-4.02-1.1.mga7.x86_64
- xpdf-common-4.02-1.1.mga7.x86_64


Ran xpdf from command line.

Viewed PDF content I created plus some album art in pdf format.  Both worked without issue.

Whiteboard: (none) => MGA7-64-OK
CC: (none) => brtians1

Comment 4 Thomas Andrews 2019-12-27 19:13:51 CET
Validating. Advisory in Comment 2.

CC: (none) => andrewsfarm, sysadmin-bugs
Keywords: (none) => validated_update

Thomas Backlund 2019-12-31 16:42:00 CET

Keywords: (none) => advisory
CC: (none) => tmb

Comment 5 Mageia Robot 2019-12-31 17:52:53 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2019-0422.html

Status: ASSIGNED => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.