Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-6265

Опубликовано: 22 сент. 2016
Источник: debian

Описание

Use-after-free vulnerability in the pdf_load_xref function in pdf/pdf-xref.c in MuPDF allows remote attackers to cause a denial of service (crash) via a crafted PDF file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mupdffixed1.9a+ds1-1.1package
mupdfnot-affectedwheezypackage

Примечания

  • http://bugs.ghostscript.com/show_bug.cgi?id=696941

  • Fixed by: https://git.ghostscript.com/?p=mupdf.git;h=fa1936405b6a84e5c9bb440912c23d532772f958

  • Possibly introduced with: https://git.ghostscript.com/?p=mupdf.git;h=e767bd783d91ae88cd79da19e79afb2c36bcf32a (1.7-rc1)

  • Although the e767bd783d91ae88cd79da19e79afb2c36bcf32a introduced the solid xrefs,

  • that part of the code went trough several iterations before it settled down, and

  • thus the issue could possibly be presend already before. The code in 1.5-1 looks

  • quite similar, although the reproducer does not lead to a heap-use-after-free in

  • the 1.5-1 case.

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 9 лет назад

Use-after-free vulnerability in the pdf_load_xref function in pdf/pdf-xref.c in MuPDF allows remote attackers to cause a denial of service (crash) via a crafted PDF file.

CVSS3: 5.5
nvd
больше 9 лет назад

Use-after-free vulnerability in the pdf_load_xref function in pdf/pdf-xref.c in MuPDF allows remote attackers to cause a denial of service (crash) via a crafted PDF file.

suse-cvrf
больше 9 лет назад

Security update for mupdf

CVSS3: 5.5
github
больше 3 лет назад

Use-after-free vulnerability in the pdf_load_xref function in pdf/pdf-xref.c in MuPDF allows remote attackers to cause a denial of service (crash) via a crafted PDF file.