SUSE has isued an advisory on June 11: https://lists.suse.com/pipermail/sle-updates/2024-June/035557.html Mageia 9 is also affected.
CVE: (none) => CVE-2024-4141Source RPM: (none) => poppler-24.06.0-1.mga10.src.rpmWhiteboard: (none) => MGA9TOOStatus comment: (none) => Patch available from openSUSE
Suggested advisory: ======================== The updated packages fix a security vulnerability: Out-of-bounds array write. (CVE-2024-4141) References: https://lists.suse.com/pipermail/sle-updates/2024-June/035557.html ======================== Updated packages in core/updates_testing: ======================== lib(64)poppler-cpp0-23.02.0-1.2.mga9 lib(64)poppler-cpp-devel-23.02.0-1.2.mga9 lib(64)poppler-devel-23.02.0-1.2.mga9 lib(64)poppler-gir0.18-23.02.0-1.2.mga9 lib(64)poppler-glib8-23.02.0-1.2.mga9 lib(64)poppler-glib-devel-23.02.0-1.2.mga9 lib(64)poppler-qt5_1-23.02.0-1.2.mga9 lib(64)poppler-qt5-devel-23.02.0-1.2.mga9 lib(64)poppler-qt6_3-23.02.0-1.2.mga9 lib(64)poppler-qt6-devel-23.02.0-1.2.mga9 lib(64)poppler126-23.02.0-1.2.mga9 poppler-23.02.0-1.2.mga9 from SRPM: poppler-23.02.0-1.2.mga9.src.rpm
Status comment: Patch available from openSUSE => (none)Status: NEW => ASSIGNEDSource RPM: poppler-24.06.0-1.mga10.src.rpm => poppler-23.02.0-1.1.mga9.src.rpmWhiteboard: MGA9TOO => (none)Version: Cauldron => 9Assignee: bugsquad => qa-bugs
Keywords: (none) => advisory
mga9, x64 No luck finding PoC. All the packages updated cleanly over the ...1.1 versions. Referred to bug 30690 for testing hints. $ pdftohtml PythonProjectsForKids.pdf A lot of diagnostic output. A file with the same name but an html extension was generated. $ firefox PythonProjectsForKids.pdf opened a new tab in Firefox, displaying the frontispiece for the book and a hyperlink page index on the left. Extracted 190 images from the same book as PPM and JPEG images, most of which are code samples. $ pdfimages PythonProjectsForKids.pdf pythonkids Separated pages 2 to 4 from a PDF file. $ pdfseparate -f 2 -l 4 The_Haunting_of_Eleanor_and_Annie.pdf page_%d lcl@yildun:books $ ls page* page_2 page_3 page_4 $ file page_3 page_3: PDF document, version 1.5, 1 pages Used xpdf to display the page, which looked fine. lcl@yildun:books $ strace -o djvu.trace pdf2djvu -o test.djv module_cheat_sheet.pdf module_cheat_sheet.pdf: - page #1 -> #1 0.021 bits/pixel; 6.080:1, 83.55% saved, 136259 bytes in, 22410 bytes out $ grep poppler djvu.trace openat(AT_FDCWD, "/usr/lib64/libpoppler.so.126", O_RDONLY|O_CLOEXEC) = 3 This all looks good so far. Giving it an OK.
CC: (none) => tarazed25Whiteboard: (none) => MGA9-64-OK
Validating.
CC: (none) => andrewsfarm, sysadmin-bugsKeywords: (none) => validated_update
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2024-0218.html
Resolution: (none) => FIXEDStatus: ASSIGNED => RESOLVED