New Debian poppler 22.12.0-2+deb12u1 fixes: This update addresses the following issues: 22.12.0-2+deb12u1 (Sat, 12 Apr 2025 21:26:36 +0300) * Non-maintainer upload. * CVE-2023-34872: OutlineItem::open crash on malformed files * CVE-2024-56378: Out-of-bounds read in JBIG2Bitmap::combine * CVE-2025-32364: Floating point exception in PSStack::roll * CVE-2025-32365: Out-of-bounds read in JBIG2:Bitmap::combine
--- mirror/ftp/pool/main/p/poppler/poppler_22.12.0-2.dsc +++ apt/ucs_5.2-0-errata5.2-1/source/poppler_22.12.0-2+deb12u1.dsc @@ -1,3 +1,15 @@ +22.12.0-2+deb12u1 [Sat, 12 Apr 2025 21:26:36 +0300] Adrian Bunk <bunk@debian.org>: + + * Non-maintainer upload. + * CVE-2023-34872: OutlineItem::open crash on malformed files + (Closes: #1042811) + * CVE-2024-56378: Out-of-bounds read in JBIG2Bitmap::combine + (Closes: #1091322) + * CVE-2025-32364: Floating point exception in PSStack::roll + (Closes: #1102190) + * CVE-2025-32365: Out-of-bounds read in JBIG2:Bitmap::combine + (Closes: #1102191) + 22.12.0-2 [Tue, 10 Jan 2023 16:36:05 -0500] Jeremy Bicha <jbicha@ubuntu.com>: * Team upload <http://piuparts.knut.univention.de/5.2-1/#1397985219442115956>
OK: bug OK: yaml OK: announce_errata OK: patch OK: piuparts [5.2-1] c023d7342e8 Bug #58288: poppler 22.12.0-2+deb12u1 doc/errata/staging/poppler.yaml | 20 ++++++++++++++++++++ 1 file changed, 20 insertions(+)
<https://errata.software-univention.de/#/?erratum=5.2x99>