Fedora Linux 8784 Published by

A mingw-podofo security update has been released for Fedora 31.



--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2020-dd79b615cd
2020-01-27 11:25:31.282972
--------------------------------------------------------------------------------

Name : mingw-podofo
Product : Fedora 31
Version : 0.9.6
Release : 13.fc31
URL :   http://podofo.sourceforge.net
Summary : MinGW Windows podofo library
Description :
MinGW Windows podofo library.

--------------------------------------------------------------------------------
Update Information:

This update fixes CVE-2019-20093.
--------------------------------------------------------------------------------
ChangeLog:

* Fri Jan 17 2020 Sandro Mani - 0.9.6-13
- Add patch for CVE-2019-20093
* Tue Oct 8 2019 Sandro Mani - 0.9.6-12
- Rebuild (Changes/Mingw32GccDwarf2)
* Tue Aug 27 2019 Sandro Mani - 0.9.6-11
- Rebuild (libidn)
--------------------------------------------------------------------------------
References:

[ 1 ] Bug #1792346 - CVE-2019-20093 podofo: NULL pointer dereference in PoDoFo::PdfVariant::DelayedLoad in PdfVariant.h [fedora-all]
  https://bugzilla.redhat.com/show_bug.cgi?id=1792346
[ 2 ] Bug #1792345 - CVE-2019-20093 mingw-podofo: podofo: NULL pointer dereference in PoDoFo::PdfVariant::DelayedLoad in PdfVariant.h [fedora-all]
  https://bugzilla.redhat.com/show_bug.cgi?id=1792345
--------------------------------------------------------------------------------

This update can be installed with the "dnf" update program. Use
su -c 'dnf upgrade --advisory FEDORA-2020-dd79b615cd' at the command
line. For more information, refer to the dnf documentation available at
  http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
  https://fedoraproject.org/keys