SB2018051133 - Heap-based buffer overflow in mupdf (Alpine package)
Published: May 11, 2018
Security Bulletin ID
SB2018051133
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Heap-based buffer overflow (CVE-ID: CVE-2018-6187)
The vulnerability allows a remote attacker to cause DoS condition on the traget system.The weakness exists in the do_pdf_save_document function in the pdf/pdf-write.c file due to heap-based buffer overflow. A remote attacker can trick the victim into opening a specially crafted pdf file, trigger memory corruption and cause the service to crash.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=d9c3c9c209f455ed747c905497cfdbfd57baa2c8
- https://git.alpinelinux.org/aports/commit/?id=44edd0a362a97c812a59af6d93f91741ddff47c6
- https://git.alpinelinux.org/aports/commit/?id=70bbeef9560773077c355e9816977d9ab61c15c6
- https://git.alpinelinux.org/aports/commit/?id=831d2ee24986330048dfa488c8bb5017656e8efd
- https://git.alpinelinux.org/aports/commit/?id=f26e75a18613c396b7491f5210d42a45aefa6031