Debian Security Advisory
DLA-24-1 poppler -- LTS security update
- Date Reported:
- 31 Jul 2014
- Affected Packages:
- poppler
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 722705.
In Mitre's CVE dictionary: CVE-2010-5110. - More information:
-
It was discovered that poppler did return program execution to the libjpeg library under error conditions, which is not expected by the library and results in application crash and possibly code execution.
For Debian 6
Squeeze
, these issues have been fixed in poppler version 0.12.4-1.2+squeeze4