Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

openSUSE 15 SP4: SUSE-SU-2022:10126-1 Moderate: mupdf Security Update

opensuse
Calendar Grey September 17, 2022
Dist Opensuse Esm H88
Corrections for two security flaws in mupdf included in the openSUSE advisory. Upgrade today for enhanced safety.
An update that fixes two vulnerabilities is now available

Description

This update for mupdf fixes the following issues:

mupdf was updated to 1.20.3:

* return error, not success when unable to lock native device resource.

* Bug 705620: Start journal operation instead of pushing local xref.

* Ensure AndroidDrawDevice is destroyed, even upon exception.

* source/pdf/pdf-clean.c: fix segv from incorrect call to fz_drop_pixmap().

* Bug 705681: Enclose code in begin/end operation.

* Guard against SEGVs when calling archive functions with NULL archive.

mupdf was updated to 1.20.0 (boo#1202858, CVE-2021-4216):

* Experimental C# bindings

* Cross compilation should no longer need a host compiler

* Major additions to JNI bindings

* New API to edit outline

* New API to resolve and create links

* New API to toggle individual layers in PDF

* Layer panel in mupdf-gl

* Layer option in mutool draw

* New API to add a Javascript console

* Console panel in mupdf-gl

* Text search API extended to be able to...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP4:

zypper in -t patch openSUSE-2022-10126=1

Package List

- openSUSE Backports SLE-15-SP4 (aarch64 ppc64le s390x x86_64):

mupdf-1.20.3-bp154.2.3.1

mupdf-devel-static-1.20.3-bp154.2.3.1

References

https://www.suse.com/security/cve/CVE-2018-25032.html

https://www.suse.com/security/cve/CVE-2021-4216.html

https://bugzilla.suse.com/1202858

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2022:10126-1
Rating: moderate
Affected Products: openSUSE Backports SLE-15-SP4 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here