A heap buffer overflow vulnerability was found in the poppler library. A maliciously crafted file could cause the application to crash. Upstream fix: https://cgit.freedesktop.org/poppler/poppler/commit/?id=b3425dd3261679958cd56c0f71995c15d2124433 References (reproducer attached): http://seclists.org/oss-sec/2016/q2/56
Created mingw-poppler tracking bugs for this issue: Affects: fedora-all [bug 1326228]
Created poppler tracking bugs for this issue: Affects: fedora-all [bug 1326226]
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Via RHSA-2016:2580 https://rhn.redhat.com/errata/RHSA-2016-2580.html