OracleVM 3.3 / 3.4 : poppler (OVMSA-2017-0147)

This script is Copyright (C) 2017 Tenable Network Security, Inc.


Synopsis :

The remote OracleVM host is missing one or more security updates.

Description :

The remote OracleVM system is missing necessary patches to address
critical security updates :

- Resolves: rhbz#1479815 (CVE-2017-9776)

- Don't crash on streams without Length

- Resolves: #1302365

- Use better default pixel size for printing of 0 width
lines

- Resolves: #1316163

- Identification of fonts directly from streams and files

- Resolves: #1208719

- Embed type1 fonts to PostScript files correctly

- Resolves: #1232210

- Fix lines disappearing when selecting paragraph

- Resolves: #614824

- Silence illegal entry in bfrange block in ToUnicode CMap

- Resolves: #710816

- Fix captions of push button fields.

- Resolves: #1191907

- Add poppler-0.12.4-CVE-2010-3702.patch (Properly
initialize parser)

- Add poppler-0.12.4-CVE-2010-3703.patch (Properly
initialize stack)

- Add poppler-0.12.4-CVE-2010-3704.patch (Fix crash in
broken pdf (code < 0))

- Resolves: #639860

See also :

http://www.nessus.org/u?a6e108d5
http://www.nessus.org/u?72469efb

Solution :

Update the affected poppler / poppler-utils packages.

Risk factor :

Medium / CVSS Base Score : 6.8
(CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P)
CVSS Temporal Score : 5.9
(CVSS2#E:ND/RL:OF/RC:C)
Public Exploit Available : false

Family: OracleVM Local Security Checks

Nessus Plugin ID: 102905 ()

Bugtraq ID: 43594
43841
43845

CVE ID: CVE-2010-3702
CVE-2010-3703
CVE-2010-3704
CVE-2017-9776

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now