SB2018051135 - Improper input validation in mupdf (Alpine package)
Published: May 11, 2018
Security Bulletin ID
SB2018051135
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper input validation (CVE-ID: CVE-2018-6544)
The vulnerability allows a remote attacker to cause DoS condition on the target system.The weakness exists in th pdf_load_obj_stm in pdf/pdf-xref.c due to it can reference the object stream recursively and therefore run out of error stack. A remote attacker can submit a specially crafted PDF document cause the service to crash.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=d9c3c9c209f455ed747c905497cfdbfd57baa2c8
- https://git.alpinelinux.org/aports/commit/?id=44edd0a362a97c812a59af6d93f91741ddff47c6
- https://git.alpinelinux.org/aports/commit/?id=70bbeef9560773077c355e9816977d9ab61c15c6
- https://git.alpinelinux.org/aports/commit/?id=831d2ee24986330048dfa488c8bb5017656e8efd
- https://git.alpinelinux.org/aports/commit/?id=f26e75a18613c396b7491f5210d42a45aefa6031