Debian Security Advisory

DSA-3563-1 poppler -- security update

Date Reported:
01 May 2016
Affected Packages:
poppler
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2015-8868.
More information:

It was discovered that a heap overflow in the Poppler PDF library may result in denial of service and potentially the execution of arbitrary code if a malformed PDF file is opened.

For the stable distribution (jessie), this problem has been fixed in version 0.26.5-2+deb8u1.

For the testing distribution (stretch), this problem has been fixed in version 0.38.0-3.

For the unstable distribution (sid), this problem has been fixed in version 0.38.0-3.

We recommend that you upgrade your poppler packages.