Free and open-source vulnerability scanner

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

Debian LTS: Security Advisory for mupdf (DLA-2765-1)

Information

Severity

Severity

Medium

Family

Family

Debian Local Security Checks

CVSSv2 Base

CVSSv2 Base

6.8

CVSSv2 Vector

CVSSv2 Vector

AV:N/AC:M/Au:N/C:P/I:P/A:P

Solution Type

Solution Type

Vendor Patch

Created

Created

2 years ago

Modified

Modified

2 years ago

Summary

The remote host is missing an update for the 'mupdf' package(s) announced via the DLA-2765-1 advisory.

Insight

Insight

Multiple issues have been discovered in mupdf. CVE-2016-10246 Buffer overflow in the main function in jstest_main.c allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted file. CVE-2016-10247 Buffer overflow in the my_getline function in jstest_main.c allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted file. CVE-2017-6060 Stack-based buffer overflow in jstest_main.c allows remote attackers to have unspecified impact via a crafted image. CVE-2018-10289 An infinite loop in the fz_skip_space function of the pdf/pdf-xref.c file. A remote adversary could leverage this vulnerability to cause a denial of service via a crafted pdf file. CVE-2018-1000036 Multiple memory leaks in the PDF parser allow an attacker to cause a denial of service (memory leak) via a crafted file. CVE-2020-19609 A heap based buffer over-write in tiff_expand_colormap() function when parsing TIFF files allowing attackers to cause a denial of service.

Affected Software

Affected Software

'mupdf' package(s) on Debian Linux.

Detection Method

Detection Method

Checks if a vulnerable package version is present on the target host.

Solution

Solution

For Debian 9 stretch, these problems have been fixed in version 1.14.0+ds1-4+deb9u1. We recommend that you upgrade your mupdf packages.