]>
dgit.raspbian.org Git - poppler.git/log
summary |
shortlog | log |
commit |
commitdiff |
tree
first ⋅ prev ⋅ next
Albert Astals Cid [Wed, 26 Mar 2025 10:26:32 +0000 (11:26 +0100)]
Make sure regex doesn't stack overflow by limiting it
Origin: https://gitlab.freedesktop.org/poppler/poppler/-/commit/
f54b815672117c250420787c8c006de98e8c7408
Bug-Debian: https://bugs.debian.org/
1117046
Bug-Debian-Security: https://security-tracker.debian.org/tracker/CVE-2025-43718
Happens with very long pdfsubver strings when compiled with
-fno-omit-frame-pointer -mno-omit-leaf-frame-pointer -flto=auto
Gbp-Pq: Name Make-sure-regex-doesn-t-stack-overflow-by-limiting-i.patch
Marek Kasik [Thu, 21 May 2026 15:51:51 +0000 (17:51 +0200)]
SplashOutputDev: Fix integer overflow in tilingPatternFill
Origin: https://gitlab.freedesktop.org/poppler/poppler/-/commit/
8352264766652b98336e92359a70b3161a9ab97a
Bug-Debian: https://bugs.debian.org/
1138708
Bug: https://gitlab.freedesktop.org/poppler/poppler/-/work_items/1715
Bug-Debian-Security: https://security-tracker.debian.org/tracker/CVE-2026-10118
Use checkedMultiply() to check integer multiplication of surface size
and number of repetitions to avoid integer overflow and possible memory issues.
Fixes: #1715
Gbp-Pq: Name SplashOutputDev-Fix-integer-overflow-in-tilingPatter.patch
Sune Vuorela [Tue, 29 Jul 2025 12:14:00 +0000 (14:14 +0200)]
[PATCH] Fix crash in pdfseparate
Don't continue recursing in PDFDoc::mark* if things looks a bit weirder
than expected
Gbp-Pq: Name CVE-2025-50420.patch
Debian freedesktop.org maintainers [Sat, 6 Jun 2026 09:07:43 +0000 (11:07 +0200)]
CVE-2025-52886
Backport of:
Backport of:
From
ac36affcc8486de38e8905a8d6547a3464ff46e5 Mon Sep 17 00:00:00 2001
From: Sune Vuorela <sune@vuorela.dk>
Date: Tue, 3 Jun 2025 00:35:19 +0200
Subject: [PATCH] Limit ammount of annots per document/page
Gbp-Pq: Name CVE-2025-52886.patch
Juraj Šarinay [Thu, 6 Mar 2025 01:02:56 +0000 (02:02 +0100)]
Properly verify adbe.pkcs7.sha1 signatures.
For signatures with non-empty encapsulated content
(typically adbe.pkcs7.sha1), we only compared hash values and
never actually checked SignatureValue within SignerInfo.
The bug introduced by
c7c0207b1cfe49a4353d6cda93dbebef4508138f
made trivial signature forgeries possible. Fix this by calling
NSS_CMSSignerInfo_Verify() after the hash values compare equal.
Origin: upstream 25.04.0
Gbp-Pq: Name CVE-2025-43903.patch
Albert Astals Cid [Mon, 31 Mar 2025 12:35:49 +0000 (14:35 +0200)]
[PATCH] Move isOk check to inside JBIG2Bitmap::combine
Origin: upstream 25.04
Gbp-Pq: Name CVE-2025-32365.patch
Albert Astals Cid [Sun, 23 Mar 2025 23:44:54 +0000 (00:44 +0100)]
[PATCH] PSStack::roll: Protect against doing int = -INT_MIN
Origin: upstream 25.04
Gbp-Pq: Name CVE-2025-32364.patch
Salvatore Bonaccorso [Sat, 6 Jun 2026 09:07:43 +0000 (11:07 +0200)]
poppler (25.03.0-5+deb13u3) trixie-security; urgency=high
* Non-maintainer upload by the Security Team.
* SplashOutputDev: Fix integer overflow in tilingPatternFill (CVE-2026-10118)
(Closes: #
1138708 )
* Make sure regex doesn't stack overflow by limiting it (CVE-2025-43718)
(Closes: #
1117046 )
* Check for duplicate entries (CVE-2025-52885) (Closes: #
1117853 )
[dgit import unpatched poppler 25.03.0-5+deb13u3]
Salvatore Bonaccorso [Sat, 6 Jun 2026 09:07:43 +0000 (11:07 +0200)]
Import poppler_25.03.0-5+deb13u3.debian.tar.xz
[dgit import tarball poppler 25.03.0-5+deb13u3 poppler_25.03.0-5+deb13u3.debian.tar.xz]
Jeremy Bícha [Tue, 4 Mar 2025 21:22:49 +0000 (16:22 -0500)]
Import poppler_25.03.0.orig.tar.xz
[dgit import orig poppler_25.03.0.orig.tar.xz]