-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Wed, 27 Sep 2017 21:30:50 +0200 Source: poppler Binary: libpoppler19 libpoppler-dev libpoppler-private-dev libpoppler-glib8 libpoppler-glib-dev gir1.2-poppler-0.18 libpoppler-qt4-3 libpoppler-qt4-dev libpoppler-cpp0 libpoppler-cpp-dev poppler-utils poppler-dbg Architecture: source amd64 Version: 0.18.4-6+deb7u3 Distribution: wheezy-security Urgency: high Maintainer: Loic Minier <lool@dooz.org> Changed-By: Markus Koschany <apo@debian.org> Description: gir1.2-poppler-0.18 - GObject introspection data for poppler-glib libpoppler-cpp-dev - PDF rendering library -- development files (CPP interface) libpoppler-cpp0 - PDF rendering library (CPP shared library) libpoppler-dev - PDF rendering library -- development files libpoppler-glib-dev - PDF rendering library -- development files (GLib interface) libpoppler-glib8 - PDF rendering library (GLib-based shared library) libpoppler-private-dev - PDF rendering library -- private development files libpoppler-qt4-3 - PDF rendering library (Qt 4 based shared library) libpoppler-qt4-dev - PDF rendering library -- development files (Qt 4 interface) libpoppler19 - PDF rendering library poppler-dbg - PDF rendering library -- debugging symbols poppler-utils - PDF utilities (based on Poppler) Changes: poppler (0.18.4-6+deb7u3) wheezy-security; urgency=high . * Non-maintainer upload by the LTS team. * Fix the following CVEs: - CVE-2017-14517: NULL Pointer Dereference in the XRef::parseEntry() function in XRef.cc - CVE-2017-14617: potential buffer overflow in the ImageStream class in Stream.cc, which may lead to a denial of service or other unspecified impact. - CVE-2017-14519: memory corruption occurs in a call to Object::streamGetChar that may lead to a denial of service or other unspecified impact. Checksums-Sha1: c2e1efe7d23c2cfbf89de0c3d3bf331e63f0a5b1 3180 poppler_0.18.4-6+deb7u3.dsc d61fb84863c270cd88c99e81f152812a88fd318a 25827 poppler_0.18.4-6+deb7u3.debian.tar.gz 7ebdae51ec0e46900a2c8d2155826b22937f3598 1110570 libpoppler19_0.18.4-6+deb7u3_amd64.deb 6c0e2430ce5a7a49f025663ff5d62175a7e7a803 919918 libpoppler-dev_0.18.4-6+deb7u3_amd64.deb 253ca0e94098815c37fad6081f84a70bde300e4f 211712 libpoppler-private-dev_0.18.4-6+deb7u3_amd64.deb 1388d69306ed1fb1cfdc524c89ec556f067cb17c 106922 libpoppler-glib8_0.18.4-6+deb7u3_amd64.deb f3da5b75ad6318f49399caea38ba13a55f8f772f 233778 libpoppler-glib-dev_0.18.4-6+deb7u3_amd64.deb 5d07a7b7e272e54fdd2b4922785b66dd7c129b92 29464 gir1.2-poppler-0.18_0.18.4-6+deb7u3_amd64.deb fb2f01a1bee750897891854fc5746b7709a1f85b 141066 libpoppler-qt4-3_0.18.4-6+deb7u3_amd64.deb c5d11429160c189164f0a6476a5ffa2dcc580ba9 191836 libpoppler-qt4-dev_0.18.4-6+deb7u3_amd64.deb 48af6cd02e8ba370cc5e25eb9d3b21c2a1ebc874 48490 libpoppler-cpp0_0.18.4-6+deb7u3_amd64.deb c665ba1f8ef03df5a3feb560c0bc6e17db03573b 56736 libpoppler-cpp-dev_0.18.4-6+deb7u3_amd64.deb cc2d72c3fa9b147852ab4bb41859690ca0fc484e 163590 poppler-utils_0.18.4-6+deb7u3_amd64.deb 543107b545b202f0636f5e0f9bda4bd02f0c1e39 5182460 poppler-dbg_0.18.4-6+deb7u3_amd64.deb Checksums-Sha256: 1e79d88e402761fb3be27c8e0685eef759a5beb5ed2e6517be0b90d2ea5e85fb 3180 poppler_0.18.4-6+deb7u3.dsc 34ade574abc52651f1404981967e62e9428afe43605c12bf82881625bd214bd3 25827 poppler_0.18.4-6+deb7u3.debian.tar.gz 2ef86cb0ea020b629b454c80baf85e27150d6b0c7d0e4251833c3f22e5d57221 1110570 libpoppler19_0.18.4-6+deb7u3_amd64.deb 0d201ae0d5e312653e4dbd971b73fecc73d4684eb018729942b7032068866146 919918 libpoppler-dev_0.18.4-6+deb7u3_amd64.deb 183532848c69e79fc6efe05068be9460ec8c975c33bfce40999cefc8b5195538 211712 libpoppler-private-dev_0.18.4-6+deb7u3_amd64.deb 407a5cc16471af836e4f6406ac00d6d7b2293b3f66ddf95f5d1edae039fe290d 106922 libpoppler-glib8_0.18.4-6+deb7u3_amd64.deb 41e84d8b9ab419d9d8e4ae3cf93d65c680e4ae9e119369b8dadc02fa5f82d12a 233778 libpoppler-glib-dev_0.18.4-6+deb7u3_amd64.deb 503e188c3c1fe3d535838fb8bcf7594ef667bba1bd0a030c582b6736580ac79e 29464 gir1.2-poppler-0.18_0.18.4-6+deb7u3_amd64.deb 87ad670997d7448c8c3c4a669bb54861e65b0cdaaf0db87740480d98bf8d7bc8 141066 libpoppler-qt4-3_0.18.4-6+deb7u3_amd64.deb 73bd4ba81f7787a8ce1a8df29e2b6b22ed27f2e0ea9467d4acc5110ef672d9db 191836 libpoppler-qt4-dev_0.18.4-6+deb7u3_amd64.deb 7bc9b2a5c604fc4faa980f2d135409d351dd47f3fce473be1dcb5d3ff06ed516 48490 libpoppler-cpp0_0.18.4-6+deb7u3_amd64.deb 3a2547b8f8b23453fc9a054371902faaf8eae974aecb21ecf62215d3a43a785f 56736 libpoppler-cpp-dev_0.18.4-6+deb7u3_amd64.deb 601ea4091e40df60605af082ae03d4a21a7bd3a573a7d9e6453141722ec6767f 163590 poppler-utils_0.18.4-6+deb7u3_amd64.deb ae607e6ff801bc8b9c54f278e5964ec4c9700971a99cdb8956147f9cb1fb49fc 5182460 poppler-dbg_0.18.4-6+deb7u3_amd64.deb Files: 5a35a9e8be257fb6832db325feac9efa 3180 devel optional poppler_0.18.4-6+deb7u3.dsc 4518903209631cd2b32f4666b8d6f2e3 25827 devel optional poppler_0.18.4-6+deb7u3.debian.tar.gz 73662c3fa132b0a12e23f7b7e9b404eb 1110570 libs optional libpoppler19_0.18.4-6+deb7u3_amd64.deb faf9a141588350df623e2f1d6a583ec0 919918 libdevel optional libpoppler-dev_0.18.4-6+deb7u3_amd64.deb 7ec724abefeacc723866e6ca3f7f3508 211712 libdevel optional libpoppler-private-dev_0.18.4-6+deb7u3_amd64.deb 4b672d1fa374ea1e7251e93eff283ff5 106922 libs optional libpoppler-glib8_0.18.4-6+deb7u3_amd64.deb 414841c952d4a40fb06be30e7fd71065 233778 libdevel optional libpoppler-glib-dev_0.18.4-6+deb7u3_amd64.deb 02d15a231859a8a0ca49ef664567e4db 29464 introspection optional gir1.2-poppler-0.18_0.18.4-6+deb7u3_amd64.deb 09552e8f8e50eeac7a20b228bc78104a 141066 libs optional libpoppler-qt4-3_0.18.4-6+deb7u3_amd64.deb 9d6555003120d12af4be7ffb28bcc8d1 191836 libdevel optional libpoppler-qt4-dev_0.18.4-6+deb7u3_amd64.deb 7f23a89cfd0b6f3d71f126be2a2c41c5 48490 libs optional libpoppler-cpp0_0.18.4-6+deb7u3_amd64.deb 840b725d75fb20b1f475f640896faf2d 56736 libdevel optional libpoppler-cpp-dev_0.18.4-6+deb7u3_amd64.deb 0882aaa997a19401d47f013abaa49179 163590 utils optional poppler-utils_0.18.4-6+deb7u3_amd64.deb d13423844ca428fd48a70ac76af8d3a1 5182460 debug extra poppler-dbg_0.18.4-6+deb7u3_amd64.deb -----BEGIN PGP SIGNATURE----- iQKjBAEBCgCNFiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAlnMAKNfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQPHGFwb0BkZWJp YW4ub3JnAAoJENmtFLlRO1Hkg9IQAJKkO/bZxMQIS+ZOttCPu5psXcvr+sQKE7rp avn8Gz6MS14UAndKx8uACc5xELZ2Dbv2l0FHekMISotAsWK3QpGixFZ6JJ7/saDb FwsApOl3sxCHUJV8K0T66cREvkn9jxaIgC1JfZ3p0HhZlM17GwwXHFdwasQZN6bG GF/F+X3amZEFwxv3mgQIZIWdAnMtbeLtPA1WK1PRKzLn70tuPdOH6qAdny2nWfya Z87v9xPTKEWLtKGUWyej516P5o7N+QoHzFnd/RChXsAYzBhAkqXCpAHODDpLKUwE e+i6TFMbX/XIIlS0JVlfdiOhFRAFzFwYLNbRUpVLlfCFmI4cPO1pYYxaZqUmh8+v pzvDudKpM6AF/QT/erV+wCSz+pWY6GCAQMj0cD+jA01lgnHfyJ657/+UCHkePl1N kzjOeQUpxVqCr6qytVuR05Cuz8/fEZpddd5ExRKrbz+KqCF92pIjkTXgJqYPt74T oiCJN1z/yYLWhMIJwuxopPrZwdcc8j6efnfG6TOLfPaIM1Pll0K4lIIi0Dybc28m hTZ8q5F+F+IvZboh1Mpq6OaN5EHoyqG3Xsn2B5W64Dyoo08oRNsh/FfoIKTwLdko tPivqbbf57jy31EZGuIVuWzKC5aRrYUgowGjrUi0arAIkm6331cMIOYPGShHx031 J2BYMO2X =NRvJ -----END PGP SIGNATURE-----