Skip to content
GitLab
Explore
Sign in
Register
Commits on Source (2)
CVE-2019-10871/poppler: reference upstream fix, unset jessie postposned
· c1c6bd84
Sylvain Beucler
authored
Oct 05, 2019
c1c6bd84
dla: add poppler
· 26a2d714
Sylvain Beucler
authored
Oct 05, 2019
26a2d714
Show whitespace changes
Inline
Side-by-side
data/CVE/list
View file @
26a2d714
...
...
@@ -18819,8 +18819,9 @@ CVE-2019-10871 (An issue was discovered in Poppler 0.74.0. There is a heap-based
- poppler <unfixed> (low; bug #926529)
[buster] - poppler <postponed> (Revisit when fixed upstream)
[stretch] - poppler <postponed> (Revisit when fixed upstream)
[jessie] - poppler <postponed> (Revisit when fixed upstream)
NOTE: https://gitlab.freedesktop.org/poppler/poppler/issues/751
NOTE: https://gitlab.freedesktop.org/poppler/poppler/merge_requests/266 (rejected in favor of always enabling SPLASH_CMYK)
NOTE: https://gitlab.freedesktop.org/poppler/poppler/merge_requests/341 (always enable SPLASH_CMYK)
CVE-2019-10870
RESERVED
CVE-2019-10869 (Path Traversal and Unrestricted File Upload exists in the Ninja Forms ...)
data/dla-needed.txt
View file @
26a2d714
...
...
@@ -120,6 +120,8 @@ pam-python
--
polarssl
--
poppler
--
radare2
NOTE: 20190816: Affected by CVE-2019-14745. Vulnerable code is in
NOTE: libr/core/bin.c. Many no-dsa issues in Jessie and Stretch.
...
...