Upstream information

CVE-2009-3607 at MITRE

Description

Integer overflow in the create_surface_from_thumbnail_data function in glib/poppler-page.cc in Poppler 0.x allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information.

SUSE information

CVSS v2 Scores
  National Vulnerability Database
Base Score 9.33
Vector AV:N/AC:M/Au:N/C:C/I:C/A:C
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact Complete
Integrity Impact Complete
Availability Impact Complete
SUSE Bugzilla entries: 546393 [RESOLVED / FIXED], 566697 [RESOLVED / FIXED]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Linux Enterprise Desktop 12
  • libpoppler-glib8 >= 0.24.4-3.14
  • libpoppler-qt4-4 >= 0.24.4-3.13
  • libpoppler44 >= 0.24.4-3.14
  • poppler-tools >= 0.24.4-3.14
Patchnames:
SUSE Linux Enterprise Desktop 12 GA libpoppler-glib8
SUSE Linux Enterprise Desktop 12 SP1
  • libpoppler-glib8 >= 0.24.4-3.14
  • libpoppler-qt4-4 >= 0.24.4-3.13
  • libpoppler44 >= 0.24.4-3.14
  • poppler-tools >= 0.24.4-3.14
Patchnames:
SUSE Linux Enterprise Desktop 12 SP1 GA libpoppler-glib8
SUSE Linux Enterprise Desktop 12 SP2
  • libpoppler-glib8 >= 0.43.0-15.1
  • libpoppler-qt4-4 >= 0.43.0-15.1
  • libpoppler44 >= 0.24.4-12.1
  • libpoppler60 >= 0.43.0-15.1
  • poppler-tools >= 0.43.0-15.1
Patchnames:
SUSE Linux Enterprise Desktop 12 SP2 GA libpoppler-glib8
SUSE Linux Enterprise Desktop 12 SP2 GA libpoppler44
SUSE Linux Enterprise Server 11
  • libpoppler-glib4 >= 0.10.1-1.31.1
  • libpoppler-qt4-3 >= 0.10.1-1.31.1
  • libpoppler4 >= 0.10.1-1.31.1
  • poppler-tools >= 0.10.1-1.31.1
Patchnames:
slessp0-libpoppler-devel
SUSE Linux Enterprise Server 11 SP2
  • libpoppler-glib4 >= 0.12.3-1.3.1
  • libpoppler-qt4-3 >= 0.12.3-1.3.1
  • libpoppler5 >= 0.12.3-1.3.1
  • poppler-tools >= 0.12.3-1.3.1
Patchnames:
SUSE Linux Enterprise Server 11 SP2 GA libpoppler-glib4
SUSE Linux Enterprise Server 11 SP3
  • libpoppler-glib4 >= 0.12.3-1.8.1
  • libpoppler-qt4-3 >= 0.12.3-1.8.1
  • libpoppler5 >= 0.12.3-1.8.1
  • poppler-tools >= 0.12.3-1.8.1
Patchnames:
SUSE Linux Enterprise Server 11 SP3 GA libpoppler-glib4
SUSE Linux Enterprise Server 11 SP4
  • libpoppler-glib4 >= 0.12.3-1.10.1
  • libpoppler-qt4-3 >= 0.12.3-1.10.1
  • libpoppler5 >= 0.12.3-1.10.1
  • poppler-tools >= 0.12.3-1.10.1
Patchnames:
SUSE Linux Enterprise Server 11 SP4 GA libpoppler-glib4
SUSE Linux Enterprise Server 12
  • libpoppler-glib8 >= 0.24.4-3.8
  • libpoppler-qt4-4 >= 0.24.4-3.9
  • libpoppler44 >= 0.24.4-3.8
  • poppler-tools >= 0.24.4-3.8
Patchnames:
SUSE Linux Enterprise Server 12 GA libpoppler-glib8
SUSE Linux Enterprise Server 12 SP1
  • libpoppler-glib8 >= 0.24.4-3.14
  • libpoppler-qt4-4 >= 0.24.4-3.13
  • libpoppler44 >= 0.24.4-3.14
  • poppler-tools >= 0.24.4-3.14
Patchnames:
SUSE Linux Enterprise Server 12 SP1 GA libpoppler-glib8
SUSE Linux Enterprise Server 12 SP2
  • libpoppler-glib8 >= 0.43.0-15.1
  • libpoppler-qt4-4 >= 0.43.0-15.1
  • libpoppler44 >= 0.24.4-12.1
  • libpoppler60 >= 0.43.0-15.1
  • poppler-tools >= 0.43.0-15.1
Patchnames:
SUSE Linux Enterprise Server 12 SP2 GA libpoppler-glib8
SUSE Linux Enterprise Server 12 SP2 GA libpoppler44
SUSE Linux Enterprise Server for Raspberry Pi 12 SP2
  • libpoppler-glib8 >= 0.43.0-15.1
  • libpoppler-qt4-4 >= 0.43.0-15.1
  • libpoppler44 >= 0.24.4-12.1
  • libpoppler60 >= 0.43.0-15.1
  • poppler-tools >= 0.43.0-15.1
Patchnames:
SUSE Linux Enterprise Server for Raspberry Pi 12 SP2 GA libpoppler-glib8
SUSE Linux Enterprise Server for Raspberry Pi 12 SP2 GA libpoppler44
SUSE Linux Enterprise Software Development Kit 11 SP4
  • libpoppler-devel >= 0.12.3-1.10.1
  • libpoppler-glib-devel >= 0.12.3-1.10.1
  • libpoppler-qt2 >= 0.12.3-1.10.1
  • libpoppler-qt3-devel >= 0.12.3-1.10.1
  • libpoppler-qt4-devel >= 0.12.3-1.10.1
  • poppler-tools >= 0.12.3-1.10.1
Patchnames:
SUSE Linux Enterprise Software Development Kit 11 SP4 GA libpoppler-devel
SUSE Linux Enterprise Software Development Kit 12
  • libpoppler-devel >= 0.24.4-3.14
  • libpoppler-glib-devel >= 0.24.4-3.14
  • libpoppler-qt4-devel >= 0.24.4-3.13
  • typelib-1_0-Poppler-0_18 >= 0.24.4-3.14
Patchnames:
SUSE Linux Enterprise Software Development Kit 12 GA libpoppler-devel
SUSE Linux Enterprise Software Development Kit 12 SP1
  • libpoppler-devel >= 0.24.4-3.14
  • libpoppler-glib-devel >= 0.24.4-3.14
  • libpoppler-qt4-devel >= 0.24.4-3.13
  • typelib-1_0-Poppler-0_18 >= 0.24.4-3.14
Patchnames:
SUSE Linux Enterprise Software Development Kit 12 SP1 GA libpoppler-devel
SUSE Linux Enterprise Software Development Kit 12 SP2
  • libpoppler-cpp0 >= 0.43.0-15.1
  • libpoppler-devel >= 0.43.0-15.1
  • libpoppler-glib-devel >= 0.43.0-15.1
  • libpoppler-qt4-devel >= 0.43.0-15.1
  • typelib-1_0-Poppler-0_18 >= 0.43.0-15.1
Patchnames:
SUSE Linux Enterprise Software Development Kit 12 SP2 GA libpoppler-cpp0
openSUSE 11.1
  • poppler-debuginfo >= 0.10.1-1.7.1
  • poppler-debugsource >= 0.10.1-1.7.1
openSUSE 11.1
  • libpoppler-devel >= 0.10.1-1.7.1
  • libpoppler-doc >= 0.10.1-1.7.1
  • libpoppler-glib-devel >= 0.10.1-1.7.1
  • libpoppler-glib4 >= 0.10.1-1.7.1
  • libpoppler-qt2 >= 0.10.1-1.7.1
  • libpoppler-qt3-devel >= 0.10.1-1.7.1
  • libpoppler-qt4-3 >= 0.10.1-1.7.1
  • libpoppler-qt4-devel >= 0.10.1-1.7.1
  • libpoppler4 >= 0.10.1-1.7.1
  • poppler-tools >= 0.10.1-1.7.1
SUSE Linux Enterprise 11 Moblin 2.0
  • poppler-debuginfo >= 0.11.2-1.7.1
  • poppler-debugsource >= 0.11.2-1.7.1
SAT Patch Nr: 1932
SUSE Linux Enterprise 11 Moblin 2.0
  • libpoppler-glib4 >= 0.11.2-1.7.1
  • libpoppler4 >= 0.10.1-1.34.3
  • libpoppler5 >= 0.11.2-1.7.1
SAT Patch Nr: 1932
openSUSE 11.2
  • libpoppler-qt2-debuginfo >= 0.12.0-2.1.1
  • poppler-debugsource >= 0.12.0-2.1.1
openSUSE 11.2
  • libpoppler-devel >= 0.12.0-2.1.1
  • libpoppler-doc >= 0.12.0-2.1.1
  • libpoppler-glib-devel >= 0.12.0-2.1.1
  • libpoppler-glib4 >= 0.12.0-2.1.1
  • libpoppler-qt2 >= 0.12.0-2.1.1
  • libpoppler-qt3-devel >= 0.12.0-2.1.1
  • libpoppler-qt4-3 >= 0.12.0-2.1.1
  • libpoppler-qt4-devel >= 0.12.0-2.1.1
  • libpoppler5 >= 0.12.0-2.1.1
  • poppler-tools >= 0.12.0-2.1.1
SUSE Linux Enterprise SDK 11 GA
  • libpoppler-devel >= 0.10.1-1.31.1
  • libpoppler-glib-devel >= 0.10.1-1.31.1
  • libpoppler-qt2 >= 0.10.1-1.31.1
  • libpoppler-qt3-devel >= 0.10.1-1.31.1
  • libpoppler-qt4-devel >= 0.10.1-1.31.1
  • poppler-tools >= 0.10.1-1.31.1
sle11-sdk.ia64
sle11-debuginfo.x86-64
sle11-sdk.x86-64
sles11.x86-64
sle11-debuginfo.s390x
sled11.x86
sles11.x86
sle11-sdk.ppc
sles11.s390x
sle11-debuginfo.x86
sle11-debuginfo.ppc
sle11-debuginfo.ia64
sles11.ia64
sled11.x86-64
sle11-sdk.x86
sles11.ppc
sle11-sdk.s390x
SAT Patch Nr: 1731
SUSE Linux Enterprise SDK 11 GA
  • libpoppler-devel >= 0.10.1-1.31.1
  • libpoppler-glib-devel >= 0.10.1-1.31.1
  • libpoppler-qt2 >= 0.10.1-1.31.1
  • libpoppler-qt3-devel >= 0.10.1-1.31.1
  • libpoppler-qt4-devel >= 0.10.1-1.31.1
sle11-sdk.ia64
sle11-debuginfo.x86-64
sle11-sdk.x86-64
sles11.x86-64
sle11-debuginfo.s390x
sled11.x86
sles11.x86
sle11-sdk.ppc
sles11.s390x
sle11-debuginfo.x86
sle11-debuginfo.ppc
sle11-debuginfo.ia64
sles11.ia64
sled11.x86-64
sle11-sdk.x86
sles11.ppc
sle11-sdk.s390x
SAT Patch Nr: 1731
SUSE Linux Enterprise Desktop 11 GA
  • libpoppler-glib4 >= 0.10.1-1.31.1
  • libpoppler-qt4-3 >= 0.10.1-1.31.1
  • libpoppler4 >= 0.10.1-1.31.1
sle11-sdk.ia64
sle11-debuginfo.x86-64
sle11-sdk.x86-64
sles11.x86-64
sle11-debuginfo.s390x
sled11.x86
sles11.x86
sle11-sdk.ppc
sles11.s390x
sle11-debuginfo.x86
sle11-debuginfo.ppc
sle11-debuginfo.ia64
sles11.ia64
sled11.x86-64
sle11-sdk.x86
sles11.ppc
sle11-sdk.s390x
SAT Patch Nr: 1731
SUSE Linux Enterprise Server 11 GA
  • libpoppler-glib4 >= 0.10.1-1.31.1
  • libpoppler-qt4-3 >= 0.10.1-1.31.1
  • libpoppler4 >= 0.10.1-1.31.1
  • poppler-tools >= 0.10.1-1.31.1
sle11-sdk.ia64
sle11-debuginfo.x86-64
sle11-sdk.x86-64
sles11.x86-64
sle11-debuginfo.s390x
sled11.x86
sles11.x86
sle11-sdk.ppc
sles11.s390x
sle11-debuginfo.x86
sle11-debuginfo.ppc
sle11-debuginfo.ia64
sles11.ia64
sled11.x86-64
sle11-sdk.x86
sles11.ppc
sle11-sdk.s390x
SAT Patch Nr: 1731
openSUSE 11.0
  • poppler-debuginfo >= 0.8.2-1.5
  • poppler-debugsource >= 0.8.2-1.5
openSUSE 11.0
  • libpoppler-devel >= 0.8.2-1.5
  • libpoppler-doc >= 0.8.2-1.5
  • libpoppler-glib-devel >= 0.8.2-1.5
  • libpoppler-glib3 >= 0.8.2-1.5
  • libpoppler-qt2 >= 0.8.2-1.5
  • libpoppler-qt3-devel >= 0.8.2-1.5
  • libpoppler-qt4-3 >= 0.8.2-1.5
  • libpoppler-qt4-devel >= 0.8.2-1.5
  • libpoppler3 >= 0.8.2-1.5
  • poppler-tools >= 0.8.2-1.5
openSUSE 13.2
  • libpoppler-cpp0 >= 0.26.5-1.1
  • libpoppler-devel >= 0.26.5-1.1
  • libpoppler-glib8 >= 0.26.5-1.1
  • libpoppler-qt4-4 >= 0.26.5-1.1
  • libpoppler-qt4-devel >= 0.26.5-1.1
  • libpoppler46 >= 0.26.5-1.1
  • poppler-tools >= 0.26.5-1.1
Patchnames:
openSUSE 13.2 GA libpoppler-cpp0
openSUSE Leap 42.1
  • libpoppler-devel >= 0.24.4-5.3
  • libpoppler-glib8 >= 0.24.4-5.3
  • libpoppler-qt4-4 >= 0.24.4-5.2
  • libpoppler44 >= 0.24.4-5.3
  • poppler-tools >= 0.24.4-5.3
Patchnames:
openSUSE Leap 42.1 GA libpoppler-devel
openSUSE Leap 42.2
  • libpoppler-cpp0 >= 0.43.0-1.3
  • libpoppler-devel >= 0.43.0-1.3
  • libpoppler-glib8 >= 0.43.0-1.3
  • libpoppler-qt4-4 >= 0.43.0-1.1
  • libpoppler-qt5-1 >= 0.43.0-1.3
  • libpoppler-qt5-devel >= 0.43.0-1.3
  • libpoppler60 >= 0.43.0-1.3
  • poppler-tools >= 0.43.0-1.3
Patchnames:
openSUSE Leap 42.2 GA libpoppler-cpp0
openSUSE Tumbleweed
  • libpoppler-cpp0 >= 0.49.0-1.1
  • libpoppler-cpp0-32bit >= 0.49.0-1.1
  • libpoppler-devel >= 0.49.0-1.1
  • libpoppler-glib-devel >= 0.49.0-1.1
  • libpoppler-glib8 >= 0.49.0-1.1
  • libpoppler-glib8-32bit >= 0.49.0-1.1
  • libpoppler-qt4-4 >= 0.49.0-1.1
  • libpoppler-qt4-4-32bit >= 0.49.0-1.1
  • libpoppler-qt4-devel >= 0.49.0-1.1
  • libpoppler-qt5-1 >= 0.49.0-1.1
  • libpoppler-qt5-1-32bit >= 0.49.0-1.1
  • libpoppler-qt5-devel >= 0.49.0-1.1
  • libpoppler65 >= 0.49.0-1.1
  • libpoppler65-32bit >= 0.49.0-1.1
  • poppler-tools >= 0.49.0-1.1
  • typelib-1_0-Poppler-0_18 >= 0.49.0-1.1
Patchnames:
openSUSE Tumbleweed GA libpoppler-cpp0