Debian Security Advisory

DLA-2134-1 pdfresurrect -- LTS security update

Date Reported:
05 Mar 2020
Affected Packages:
pdfresurrect
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2020-9549.
More information:

It was discovered that there was an out-of-bounds write vulnerability in pdfresurrect, a tool for extracting or scrubbing versioning data from PDF documents.

  • CVE-2020-9549

    In PDFResurrect 0.12 through 0.19, get_type in pdf.c has an out-of-bounds write via a crafted PDF document.

For Debian 8 Jessie, these problems have been fixed in version 0.12-5+deb8u1.

We recommend that you upgrade your pdfresurrect packages.

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS