SB2017040614 - Fedora 25 update for mupdf



SB2017040614 - Fedora 25 update for mupdf

Published: April 6, 2017 Updated: April 24, 2025

Security Bulletin ID SB2017040614
Severity
High
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 50% Low 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Stack overflow (CVE-ID: CVE-2016-10221)

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error within the count_entries() function in pdf-layer.c in MuPDF 1.10a. A remote attacker can create a specially crafted PDF file, trick the victim into opening it and crash, trigger stack overflow and crash the application.


2) Memory corruption (CVE-ID: CVE-2016-1022)

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The weakness exists due to boundary error. A remote attacker can create a specially crafted Web site, trick the victim into visiting it, trigger memory corruption and execute arbitrary code with privileges of the current user.

Successful exploitation of the vulnerability results in arbitrary code execution.

Remediation

Install update from vendor's website.