Code Injection in DjVuLibre - CVE-2012-6535
Published: December 3, 2013 / Updated: August 10, 2020
DjVuLibre
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
DjVuLibre before 3.5.25.3, as used in Evince, Sumatra PDF Reader, VuDroid, and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted DjVu (aka .djv) file.