USN-3350-1: poppler vulnerabilities Ubuntu Security Notice USN-3350-1 7th July, 2017 poppler vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.04 Ubuntu 16.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary poppler could be made to crash or run programs as your login if it opened a specially crafted file. Software description poppler – PDF rendering library Details Aleksandar Nikolic discovered that poppler incorrectly handled JPEG 2000images. If a user or automated system were tricked into opening a craftedPDF file, an attacker could cause a denial of service or possibly executearbitrary code with privileges of the user invoking the program.(CVE-2017-2820) Jiaqi Peng discovered that the poppler pdfunite tool incorrectly parsedcertain malformed PDF documents. If a user or automated system were trickedinto opening a crafted PDF file, an attacker could cause poppler to crash,resulting in a denial of [ more… ]