ALAS2-2020-1511

Related Vulnerabilities: CVE-2019-14494  

A divide-by-zero error was found in the way Poppler handled certain PDF files. A remote attacker could exploit this flaw by providing a malicious PDF file that, when processed by an application linked to Poppler, would crash the application causing a denial of service. (CVE-2019-14494)

ALAS2-2020-1511


Amazon Linux 2 Security Advisory: ALAS-2020-1511
Advisory Release Date: 2020-10-22 17:30 Pacific
Advisory Updated Date: 2020-10-22 22:36 Pacific
Severity: Low
References: CVE-2019-14494 

Issue Overview:

A divide-by-zero error was found in the way Poppler handled certain PDF files. A remote attacker could exploit this flaw by providing a malicious PDF file that, when processed by an application linked to Poppler, would crash the application causing a denial of service. (CVE-2019-14494)


Affected Packages:

evince


Issue Correction:
Run yum update evince to update your system.

New Packages:
aarch64:
    evince-3.28.2-10.amzn2.aarch64
    evince-libs-3.28.2-10.amzn2.aarch64
    evince-devel-3.28.2-10.amzn2.aarch64
    evince-dvi-3.28.2-10.amzn2.aarch64
    evince-nautilus-3.28.2-10.amzn2.aarch64
    evince-browser-plugin-3.28.2-10.amzn2.aarch64
    evince-debuginfo-3.28.2-10.amzn2.aarch64

i686:
    evince-3.28.2-10.amzn2.i686
    evince-libs-3.28.2-10.amzn2.i686
    evince-devel-3.28.2-10.amzn2.i686
    evince-dvi-3.28.2-10.amzn2.i686
    evince-nautilus-3.28.2-10.amzn2.i686
    evince-browser-plugin-3.28.2-10.amzn2.i686
    evince-debuginfo-3.28.2-10.amzn2.i686

src:
    evince-3.28.2-10.amzn2.src

x86_64:
    evince-3.28.2-10.amzn2.x86_64
    evince-libs-3.28.2-10.amzn2.x86_64
    evince-devel-3.28.2-10.amzn2.x86_64
    evince-dvi-3.28.2-10.amzn2.x86_64
    evince-nautilus-3.28.2-10.amzn2.x86_64
    evince-browser-plugin-3.28.2-10.amzn2.x86_64
    evince-debuginfo-3.28.2-10.amzn2.x86_64