[ubuntu/eoan-proposed] poppler 0.76.1-0ubuntu2 (Accepted)

Gianfranco Costamagna locutusofborg at debian.org
Thu May 23 14:51:13 UTC 2019


poppler (0.76.1-0ubuntu2) eoan; urgency=medium

  * SECURITY UPDATE: heap-based buffer over-read
    in JPXStream::init in JPEG2000Stream.cc
    - debian/patches/276.patch (Closes: #929423)
      upstream patch
    - CVE-2019-12293

Date: Thu, 23 May 2019 16:48:32 +0200
Changed-By: Gianfranco Costamagna <locutusofborg at debian.org>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/+source/poppler/0.76.1-0ubuntu2
-------------- next part --------------
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Thu, 23 May 2019 16:48:32 +0200
Source: poppler
Binary: libpoppler87 libpoppler-dev libpoppler-private-dev libpoppler-glib8 libpoppler-glib-dev libpoppler-glib-doc gir1.2-poppler-0.18 libpoppler-qt5-1 libpoppler-qt5-dev libpoppler-cpp0v5 libpoppler-cpp-dev poppler-utils
Architecture: source
Version: 0.76.1-0ubuntu2
Distribution: eoan
Urgency: medium
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Gianfranco Costamagna <locutusofborg at debian.org>
Description:
 gir1.2-poppler-0.18 - GObject introspection data for poppler-glib
 libpoppler-cpp-dev - PDF rendering library -- development files (CPP interface)
 libpoppler-cpp0v5 - PDF rendering library (CPP shared library)
 libpoppler-dev - PDF rendering library -- development files
 libpoppler-glib-dev - PDF rendering library -- development files (GLib interface)
 libpoppler-glib-doc - PDF rendering library -- documentation for the GLib interface
 libpoppler-glib8 - PDF rendering library (GLib-based shared library)
 libpoppler-private-dev - PDF rendering library -- private development files
 libpoppler-qt5-1 - PDF rendering library (Qt 5 based shared library)
 libpoppler-qt5-dev - PDF rendering library -- development files (Qt 5 interface)
 libpoppler87 - PDF rendering library
 poppler-utils - PDF utilities (based on Poppler)
Closes: 929423
Changes:
 poppler (0.76.1-0ubuntu2) eoan; urgency=medium
 .
   * SECURITY UPDATE: heap-based buffer over-read
     in JPXStream::init in JPEG2000Stream.cc
     - debian/patches/276.patch (Closes: #929423)
       upstream patch
     - CVE-2019-12293
Checksums-Sha1:
 ece2cb0b0c07ce607c9a0e8a2edfd9c2c6482e25 3379 poppler_0.76.1-0ubuntu2.dsc
 c2a2f242c4e749354a83e574036ae7ab68545f81 34852 poppler_0.76.1-0ubuntu2.debian.tar.xz
 5e37480cae07602c737054bf9f953802e974c880 15617 poppler_0.76.1-0ubuntu2_source.buildinfo
Checksums-Sha256:
 9f3dd78be73be8ac758a53db6274d41bb194ed92c31ea4646bdbc7f5177c2c52 3379 poppler_0.76.1-0ubuntu2.dsc
 72158f69494353156aab7384db65b07232a5fe85310ed1d3407b098d468d4215 34852 poppler_0.76.1-0ubuntu2.debian.tar.xz
 7697fe9d63e739a71ae5215f81b41c3059a6da33dac7a824bc875339df891fb6 15617 poppler_0.76.1-0ubuntu2_source.buildinfo
Files:
 576b3819231c3c2fbaa26d9d3dee4d1c 3379 devel optional poppler_0.76.1-0ubuntu2.dsc
 6e0b93b2cc23eb6a4882901e2e66b9ed 34852 devel optional poppler_0.76.1-0ubuntu2.debian.tar.xz
 fd2701963ac54aca0804635d6f5d294f 15617 devel optional poppler_0.76.1-0ubuntu2_source.buildinfo
Original-Maintainer: Debian freedesktop.org maintainers <pkg-freedesktop-maintainers at lists.alioth.debian.org>

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEkpeKbhleSSGCX3/w808JdE6fXdkFAlzmsyIACgkQ808JdE6f
Xdn7YQ/+JtYzVSvC7ItMLYn9SousLSP8REv0NNPBtwfHqXzLUApLyGKsEOx5aEor
jDp+oCOMkH3ZTibw7LxN5vPsmSjeAQYeFNzU9cVK4lp179nqeyauUIoe8WsS7LjY
ABBBw1OKd6lIvRX0hX6tJbPbsBpO6EUpPWH8U50r618Go9relcz3UzlynQfQzSPb
Zt3fD2PAOCCEJY557Sohz/BeNGov/qHDZb2uE2NFPuBoHnKnJSQ5FiCLLAh5bcNe
PE/MJwqEnnAUXGl+WYCJ6QYC/x2wwvWhDChnM/ddnykW4fNUS+EyrQsqI+aioSaj
D9/ySoRARBWu6TuZ5qb7Ooyc2+sDWflJA9kWIyHms5MXumqhkgvn5Yft+deCX+y/
ozht12g2MOm02blKD1KHQDHekbTo8iX1t/Rec5Ts6Y1EMTPW6PTMf16FRK/uxv8L
SzuVyqyvAaA4Bw9oRObg9tdvPdD6clHXiATprKQUWAFXnDBKxoS4rTr72h3EGGpm
PgD7PICDGSMWNAJcY84jqwFYNmV+HxeKzLjWkH0vZxij7I7PW8Iv5qP6QeTwqcME
VD8MwHOXMtU4BO80eDPyujm+H+tv1t9LeFO2oGMPSX6aRky64lIjYWumZfNk1d1Z
q6Or73Mhh+fFXD/iAC2yjv2Ay7FWyW1O39C6r5num+QjsZYrfTE=
=RQjT
-----END PGP SIGNATURE-----


More information about the Eoan-changes mailing list