• [gentoo-announce] [ GLSA 202401-20 ] QPDF: Buffer Overflow

    From [email protected]@21:1/5 to All on Mon Jan 15 14:10:01 2024
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    Gentoo Linux Security Advisory GLSA 202401-20
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    https://security.gentoo.org/
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

    Severity: Normal
    Title: QPDF: Buffer Overflow
    Date: January 15, 2024
    Bugs: #803110
    ID: 202401-20

    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

    Synopsis
    ========

    A vulnerability has been found in QPDF which can lead to a heap-based
    buffer overflow.

    Background
    ==========

    QPDF: A content-preserving PDF document transformer.

    Affected packages
    =================

    Package Vulnerable Unaffected
    ------------- ------------ ------------
    app-text/qpdf < 10.1.0 >= 10.1.0

    Description
    ===========

    A vulnerability has been discovered in QPDF. Please review the CVE
    identifier referenced below for details.

    Impact
    ======

    QPDF has a heap-based buffer overflow in Pl_ASCII85Decoder::write
    (called from Pl_AES_PDF::flush and Pl_AES_PDF::finish) when a certain downstream write fails.

    Workaround
    ==========

    There is no known workaround at this time.

    Resolution
    ==========

    All QPDF users should upgrade to the latest version:

    # emerge --sync
    # emerge --ask --oneshot --verbose ">=app-text/qpdf-10.1.0"

    References
    ==========

    [ 1 ] CVE-2021-36978
    https://nvd.nist.gov/vuln/detail/CVE-2021-36978

    Availability
    ============

    This GLSA and any updates to it are available for viewing at
    the Gentoo Security Website:

    https://security.gentoo.org/glsa/202401-20

    Concerns?
    =========

    Security is a primary focus of Gentoo Linux and ensuring the
    confidentiality and security of our users' machines is of utmost
    importance to us. Any security concerns should be addressed to [email protected] or alternatively, you may file a bug at https://bugs.gentoo.org.

    License
    =======

    Copyright 2024 Gentoo Foundation, Inc; referenced text
    belongs to its owner(s).

    The contents of this document are licensed under the
    Creative Commons - Attribution / Share Alike license.

    https://creativecommons.org/licenses/by-sa/2.5
    -----BEGIN PGP SIGNATURE-----

    iQIzBAEBCgAdFiEEpqTA6ABLMxh/aChGFMQkOaVy+9kFAmWlLbgACgkQFMQkOaVy +9mbsxAAuzCjSP4rnev5lDBbgs39qtF6/HFnrWdkS4IObo1LRDjdnQMkY0CBN3dV NvPmIbkzd+x1qZNrALbYE4pvOUK/8Chtaf3qamI5ea0t+RqhFvezhnFbz1F05NdV PFKPYrZOCtXRYoL2FtPeSHGnhfP7HNsGtH1u5qySqVwVLXQb2pIR09rctflSCSb3 j8sslqPkMHRTLo8FDkyagP7MzMVVDeTLX739goPQv0Jr8RaaFxFhzkL+q7UyVp0P z/NOEcCBOIODr5Vlqr78jMEj1wdWQjTGOjJtyPnU9nBHFMJTU/0u83r/T1vx5ATL +Hf+GMPIrTeHFPo572R2xEbomvGl+n8OMr+YmuDCd8AcC8NPCA+ubUTz8PlEW2Be qXF92Z00xNgko39G973/YjyPf1dB4pJSAfg2wXKRHfEcGpReo04HYMBgsrwnNvFk tsa9zSYoFfvC2BoitubEyFGxLUKZ0vy7dAdLrzpcZ8UmdMfDvhVPEvYVGZIV3OKb Oi4saBwkTKG65URGcClU24n5Oq5mHd5RXbkBdH8UFXQxuYUHTFswIZQ2xSfxduQR oNlzpMRXcf/kVSB7jcykpQ/WxjbktoQuSv3JReBu7seqlH+008DSjU8QyyMkQvGk dBgNSRTg8PAmlNqi66F/g13HMEwua3HYnRdfqstpZwrzIWri+n8=
    =YNjf
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)