SB2018051134 - Memory corruption in mupdf (Alpine package)
Published: May 11, 2018
Security Bulletin ID
SB2018051134
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory corruption (CVE-ID: CVE-2018-6192)
The vulnerability allows a remote attacker to cause DoS condition on the traget system.The weakness exists the pdf_read_new_xref function in pdf/pdf-xref.c due to segmentation violation. A remote attacker can trick the victim into opening a specially crafted pdf file, trigger memory corruption and cause the service to crash.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=d9c3c9c209f455ed747c905497cfdbfd57baa2c8
- https://git.alpinelinux.org/aports/commit/?id=44edd0a362a97c812a59af6d93f91741ddff47c6
- https://git.alpinelinux.org/aports/commit/?id=70bbeef9560773077c355e9816977d9ab61c15c6
- https://git.alpinelinux.org/aports/commit/?id=831d2ee24986330048dfa488c8bb5017656e8efd
- https://git.alpinelinux.org/aports/commit/?id=f26e75a18613c396b7491f5210d42a45aefa6031