poppler.git
4 months agoMerge poppler (25.03.0-5) import into refs/heads/workingbranch
Jeremy Bícha [Mon, 28 Jul 2025 08:55:12 +0000 (10:55 +0200)]
Merge poppler (25.03.0-5) import into refs/heads/workingbranch

4 months agoCVE-2025-52886
Debian freedesktop.org maintainers [Mon, 28 Jul 2025 08:55:12 +0000 (10:55 +0200)]
CVE-2025-52886

Backport of:

Backport of:

From ac36affcc8486de38e8905a8d6547a3464ff46e5 Mon Sep 17 00:00:00 2001
From: Sune Vuorela <sune@vuorela.dk>
Date: Tue, 3 Jun 2025 00:35:19 +0200
Subject: [PATCH] Limit ammount of annots per document/page

Gbp-Pq: Name CVE-2025-52886.patch

4 months agoProperly verify adbe.pkcs7.sha1 signatures.
Juraj Šarinay [Thu, 6 Mar 2025 01:02:56 +0000 (02:02 +0100)]
Properly verify adbe.pkcs7.sha1 signatures.

For signatures with non-empty encapsulated content
(typically adbe.pkcs7.sha1), we only compared hash values and
never actually checked SignatureValue within SignerInfo.
The bug introduced by c7c0207b1cfe49a4353d6cda93dbebef4508138f
made trivial signature forgeries possible. Fix this by calling
NSS_CMSSignerInfo_Verify() after the hash values compare equal.

Origin: upstream 25.04.0

Gbp-Pq: Name CVE-2025-43903.patch

4 months ago[PATCH] Move isOk check to inside JBIG2Bitmap::combine
Albert Astals Cid [Mon, 31 Mar 2025 12:35:49 +0000 (14:35 +0200)]
[PATCH] Move isOk check to inside JBIG2Bitmap::combine

Origin: upstream 25.04

Gbp-Pq: Name CVE-2025-32365.patch

4 months ago[PATCH] PSStack::roll: Protect against doing int = -INT_MIN
Albert Astals Cid [Sun, 23 Mar 2025 23:44:54 +0000 (00:44 +0100)]
[PATCH] PSStack::roll: Protect against doing int = -INT_MIN

Origin: upstream 25.04

Gbp-Pq: Name CVE-2025-32364.patch

4 months agopoppler (25.03.0-5) unstable; urgency=high
Jeremy Bícha [Mon, 28 Jul 2025 08:55:12 +0000 (10:55 +0200)]
poppler (25.03.0-5) unstable; urgency=high

  [ Marc Deslauriers ]
  * SECURITY UPDATE: DoS via reference count overflow
    - debian/patches/CVE-2025-52886.patch: limit amount of annots per
      document/page in poppler/Annot.cc, poppler/Page.cc.
    - CVE-2025-52886 (Closes: #1108784)

[dgit import unpatched poppler 25.03.0-5]

4 months agoImport poppler_25.03.0-5.debian.tar.xz
Jeremy Bícha [Mon, 28 Jul 2025 08:55:12 +0000 (10:55 +0200)]
Import poppler_25.03.0-5.debian.tar.xz

[dgit import tarball poppler 25.03.0-5 poppler_25.03.0-5.debian.tar.xz]

7 months agoMerge poppler (25.03.0-4) import into refs/heads/workingbranch
Jeremy Bícha [Fri, 18 Apr 2025 22:16:32 +0000 (18:16 -0400)]
Merge poppler (25.03.0-4) import into refs/heads/workingbranch

7 months agoProperly verify adbe.pkcs7.sha1 signatures.
Juraj Šarinay [Thu, 6 Mar 2025 01:02:56 +0000 (02:02 +0100)]
Properly verify adbe.pkcs7.sha1 signatures.

For signatures with non-empty encapsulated content
(typically adbe.pkcs7.sha1), we only compared hash values and
never actually checked SignatureValue within SignerInfo.
The bug introduced by c7c0207b1cfe49a4353d6cda93dbebef4508138f
made trivial signature forgeries possible. Fix this by calling
NSS_CMSSignerInfo_Verify() after the hash values compare equal.

Origin: upstream 25.04.0

Gbp-Pq: Name CVE-2025-43903.patch

7 months ago[PATCH] Move isOk check to inside JBIG2Bitmap::combine
Albert Astals Cid [Mon, 31 Mar 2025 12:35:49 +0000 (14:35 +0200)]
[PATCH] Move isOk check to inside JBIG2Bitmap::combine

Origin: upstream 25.04

Gbp-Pq: Name CVE-2025-32365.patch

7 months ago[PATCH] PSStack::roll: Protect against doing int = -INT_MIN
Albert Astals Cid [Sun, 23 Mar 2025 23:44:54 +0000 (00:44 +0100)]
[PATCH] PSStack::roll: Protect against doing int = -INT_MIN

Origin: upstream 25.04

Gbp-Pq: Name CVE-2025-32364.patch

7 months agopoppler (25.03.0-4) unstable; urgency=high
Jeremy Bícha [Fri, 18 Apr 2025 22:16:32 +0000 (18:16 -0400)]
poppler (25.03.0-4) unstable; urgency=high

  * Team upload
  * SECURITY UPDATE: Properly verify abde.pkcs7.sha1 signatures
    - Cherry-pick upstream fix for the
      NSSSignatureVerification::validateSignature function
      in NSSCryptoSignBackend.cc
    - CVE-2025-43903 (Closes: #1103545)

[dgit import unpatched poppler 25.03.0-4]

7 months agoImport poppler_25.03.0-4.debian.tar.xz
Jeremy Bícha [Fri, 18 Apr 2025 22:16:32 +0000 (18:16 -0400)]
Import poppler_25.03.0-4.debian.tar.xz

[dgit import tarball poppler 25.03.0-4 poppler_25.03.0-4.debian.tar.xz]

9 months agoImport poppler_25.03.0.orig.tar.xz
Jeremy Bícha [Tue, 4 Mar 2025 21:22:49 +0000 (16:22 -0500)]
Import poppler_25.03.0.orig.tar.xz

[dgit import orig poppler_25.03.0.orig.tar.xz]

15 months agopoppler (24.08.0-2) unstable; urgency=medium
Jeremy Bícha [Sun, 18 Aug 2024 14:46:36 +0000 (10:46 -0400)]
poppler (24.08.0-2) unstable; urgency=medium

  * Team upload
  * Release to unstable

[dgit import unpatched poppler 24.08.0-2]

15 months agoImport poppler_24.08.0-2.debian.tar.xz
Jeremy Bícha [Sun, 18 Aug 2024 14:46:36 +0000 (10:46 -0400)]
Import poppler_24.08.0-2.debian.tar.xz

[dgit import tarball poppler 24.08.0-2 poppler_24.08.0-2.debian.tar.xz]

16 months agoImport poppler_24.08.0.orig.tar.xz
Jeremy Bícha [Thu, 1 Aug 2024 23:46:39 +0000 (19:46 -0400)]
Import poppler_24.08.0.orig.tar.xz

[dgit import orig poppler_24.08.0.orig.tar.xz]