Alerts This Week
Warning Icon 1 562
Alerts This Week
Warning Icon 1 562

Debian: DSA-2844-1 Critical: Djvulibre Arbitrary Code Execution

debian
Calendar Grey January 15, 2014
Debian Logo
A vital security patch for Djvulibre addresses potential arbitrary code execution vulnerabilities. Ensure you update promptly to fortify your Debian systems.
It was discovered that djvulibre, the Open Source DjVu implementation project, can be crashed or possibly make it execute arbitrary code when processing a specially crafted djvu fi...

Summary

It was discovered that djvulibre, the Open Source DjVu implementation
project, can be crashed or possibly make it execute arbitrary code when
processing a specially crafted djvu file.

For the oldstable distribution (squeeze), this problem has been fixed in
version 3.5.23-3+squeeze1.

This problem has been fixed before the release of the stable distribution
(wheezy), therefore it is not affected.

We recommend that you upgrade your djvulibre packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: djvulibre
CVE ID: CVE-2012-6535

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here