SB2017050316 - Stack-based buffer overflow in mupdf (Alpine package)
Published: May 3, 2017
Security Bulletin ID
SB2017050316
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Stack-based buffer overflow (CVE-ID: CVE-2017-6060)
Stack-based buffer overflow in jstest_main.c in mujstest in Artifex Software, Inc. MuPDF 1.10a allows remote attackers to have unspecified impact via a crafted image.Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=d9c3c9c209f455ed747c905497cfdbfd57baa2c8
- https://git.alpinelinux.org/aports/commit/?id=831d2ee24986330048dfa488c8bb5017656e8efd
- https://git.alpinelinux.org/aports/commit/?id=4c051e672a466cabc9cb2929e26527e1a0b4f387
- https://git.alpinelinux.org/aports/commit/?id=a05cd51302237e06412d14a512a51fd1092860bb
- https://git.alpinelinux.org/aports/commit/?id=48776dcc01e07b1ebbf5f2ce5d2100f01db0b8bf