Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Debian 9 DLA-2765-1 Critical: Mupdf Denial of Service Risks

debian lts
Calendar Grey September 23, 2021
Dist Debian Esm H88
Enhance mupdf on Debian to mitigate various security vulnerabilities, including potential buffer overflow issues and risks of service disruption.
Multiple issues have been discovered in mupdf

Summary

CVE-2016-10246

Buffer overflow in the main function in jstest_main.c allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted file.


CVE-2016-10247

Buffer overflow in the my_getline function in jstest_main.c allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted file.


CVE-2017-6060

Stack-based buffer overflow in jstest_main.c allows remote attackers to have unspecified impact via a crafted image.


CVE-2018-10289

An infinite loop in the fz_skip_space function of the pdf/pdf-xref.c file.
A remote adversary could leverage this vulnerability to cause a denial of
service via a crafted pdf file.


CVE-2018-1000036

Multiple memory leaks in the PDF parser allow an attacker to cause a denial
of service (memory leak) via a crafted file.


CVE-2020-19609

A heap based buffer over-write in tiff_expand_colormap() function when parsing TIFF
files allowing attackers to cause a denial of service.


Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: mupdf
Version: 1.14.0+ds1-4+deb9u1
CVE ID: CVE-2016-10246 CVE-2016-10247 CVE-2017-6060 CVE-2018-10289

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here