Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Debian: DSA-4006-1 Moderate: Mupdf Denial Of Service and Threat

debian
Calendar Grey October 24, 2017
Debian Logo
A series of flaws in MuPDF have been identified, resulting in potential denial of service and arbitrary code execution risks. It is advised to apply updates promptly.
Multiple vulnerabilities have been found in MuPDF, a PDF file viewer, which may result in denial of service or the execution of arbitrary code

Summary

CVE-2017-14685, CVE-2017-14686, and CVE-2017-14687

WangLin discovered that a crafted .xps file can crash MuPDF and
potentially execute arbitrary code in several ways, since the
application makes unchecked assumptions on the entry format.

CVE-2017-15587

Terry Chia and Jeremy Heng discovered an integer overflow that can
cause arbitrary code execution via a crafted .pdf file.

For the stable distribution (stretch), these problems have been fixed in
version 1.9a+ds1-4+deb9u1.

We recommend that you upgrade your mupdf packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Package: mupdf
CVE ID: CVE-2017-14685 CVE-2017-14686 CVE-2017-14687 CVE-2017-15587

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here