Poppler: Arbitrary Code Execution — GLSA 202209-21

A vulnerability has been discovered in Poppler which could allow for arbitrary code execution.

Affected packages

app-text/poppler on all architectures
Affected versions < 22.09.0
Unaffected versions >= 22.09.0

Background

Poppler is a PDF rendering library based on the xpdf-3.0 code base.

Description

Multiple vulnerabilities have been discovered in Poppler. Please review the CVE identifiers referenced below for details.

Impact

Processing a specially crafted PDF file or JBIG2 image could lead to a crash or the execution of arbitrary code.

Workaround

Avoid opening untrusted PDFs.

Resolution

All Poppler users should upgrade to the latest version:

 # emerge --sync
 # emerge --ask --oneshot --verbose ">=app-text/poppler-22.09.0"
 

References

Release date
September 29, 2022

Latest revision
September 29, 2022: 1

Severity
high

Exploitable
remote

Bugzilla entries