Debian Security Advisory

DLA-2475-1 pdfresurrect -- LTS security update

Date Reported:
01 Dec 2020
Affected Packages:
pdfresurrect
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2019-14934, CVE-2020-20740.
More information:

Vulnerabilities have been discovered in pdfresurrect, a tool for analyzing and manipulating revisions to PDF documents.

  • CVE-2019-14934

    pdf_load_pages_kids in pdf.c doesn't validate a certain size value, which leads to a malloc failure and out-of-bounds write

  • CVE-2020-20740

    lack of header validation checks causes heap-buffer-overflow in pdf_get_version()

For Debian 9 stretch, these problems have been fixed in version 0.12-6+deb9u1.

We recommend that you upgrade your pdfresurrect packages.

For the detailed security status of pdfresurrect please refer to its security tracker page at: https://security-tracker.debian.org/tracker/pdfresurrect

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS