fix(cve): CVE-2025-59798 - pdfwrite - avoid buffer overrun - #7
Conversation
CVE: CVE-2025-59798 (medium) - Buffer overflow in pdf_write_cmap Upstream: ArtifexSoftware/ghostpdl@0cae41b Co-authored-by: hudeng <hudeng@deepin.org> Generated-By: qwen3.6-35b
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
|
/hold |
|
TAG Bot TAG: 10.05.1_dfsg-3deepin3 |
CVE: CVE-2025-59800 (medium) - Heap overflow in ocr_line8 - PDF OCR 8 bit device raster size calculation overflow vulnerability Upstream: ArtifexSoftware/ghostpdl@176cf01 Co-authored-by: hudeng <hudeng@deepin.org> Generated-By: qwen3.6-35b
CVE: CVE-2025-59801 (medium) - In Artifex GhostXPS before 10.06.0, there is a stack-based buffer overflow in xps_unpredict_tiff in xpstiff.c because the samplesperpixel value is not checked. Upstream: ArtifexSoftware/ghostpdl@d12002b Co-authored-by: hudeng <hudeng@deepin.org> Generated-By: qwen3.6-35b
审查结论:暂不建议合并(存在合并冲突)[P1] 与 master 冲突,CVE-2025-59800/59801 补丁已在 master 上存在本 PR 基于旧 master 经比对:PR 与 master 的 建议:将分支 rebase 到当前 master,丢弃重复的 59800/59801 两个 commit,仅保留 59798 的补丁与 changelog 条目后重新提交。 唯一新增补丁 CVE-2025-59798 的质量验证(合格)该补丁与上游
修复逻辑正确、内存释放路径完整,补丁本身无问题。 结论: |
Resolve conflicts: - debian/patches/series: keep master's CVE ordering (59801, 59800) plus the PR's unique CVE-2025-59798.patch - debian/patches/CVE-2025-5980{0,1}.patch: take master's canonical versions (identical patch body, fixed trailing newline) - debian/changelog: keep PR branch's granular entries (deepin2/3/4 for CVE-2025-59798/59800/59801)
The previous merge rewrote master's existing 10.05.1~dfsg-3deepin2 (which carries CVE-2025-59801 and CVE-2025-59800) to mean CVE-2025-59798, and renumbered those two CVEs up to deepin3/deepin4, changing the meaning of an already-existing version. Restore master's deepin2 entry verbatim and add the PR's unique CVE-2025-59798 as a new 10.05.1~dfsg-3deepin3 entry on top.
|
/integrate |
|
AutoIntegrationPr Bot |
CVE: CVE-2025-59798 (medium) - Buffer overflow in pdf_write_cmap
Upstream: ArtifexSoftware/ghostpdl@0cae41b
Co-authored-by: hudeng hudeng@deepin.org
Generated-By: qwen3.6-35b
CVE: CVE-2025-59800 (medium) - Heap overflow in ocr_line8 - PDF OCR 8 bit device raster size calculation overflow vulnerability
Upstream: ArtifexSoftware/ghostpdl@176cf01
Co-authored-by: hudeng hudeng@deepin.org
Generated-By: qwen3.6-35b
CVE: CVE-2025-59801 (medium) - In Artifex GhostXPS before 10.06.0, there is a stack-based buffer overflow in xps_unpredict_tiff in xpstiff.c because the samplesperpixel value is not checked.
Upstream: ArtifexSoftware/ghostpdl@d12002b
Co-authored-by: hudeng hudeng@deepin.org
Generated-By: qwen3.6-35b