Integer overflow in Artifex jbig2dec - CVE-2017-7976
Published: May 24, 2017 / Updated: August 30, 2017
Vulnerability identifier: #VU6704
CSH Severity: Medium
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-7976
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to obtain potentially sensitive information or cause DoS condition.
The weakness exists due to integer overflow in the jbig2_image_compose function in jbig2_image.c during operations on a crafted .jb2 file. A remote attacker can send a specially crafted .jb2 file, trigger out-of-bounds writes and access arbitrary files from process memory, cause the application to crash or possibly execute arbitrary code.
Successful exploitation of the vulnerability may result in system compromise.
The weakness exists due to integer overflow in the jbig2_image_compose function in jbig2_image.c during operations on a crafted .jb2 file. A remote attacker can send a specially crafted .jb2 file, trigger out-of-bounds writes and access arbitrary files from process memory, cause the application to crash or possibly execute arbitrary code.
Successful exploitation of the vulnerability may result in system compromise.
Affected software
Artifex jbig2dec
Gentoo Linux
Debian Linux
Fedora
Ubuntu
jbig2dec
mupdf
ghostscript
Gentoo Linux
Debian Linux
Fedora
Ubuntu
jbig2dec
mupdf
ghostscript
How to mitigate CVE-2017-7976
Install update from vendor's website.
jbig2dec - addressed in versions 0.12-4.el7, 0.12-4.fc25, 0.13-3.fc26
mupdf - addressed in versions 1.10a-6.fc25, 1.10a-6.fc26, 1.10a-7.fc25
ghostscript - addressed in versions 9.20-9.fc24, 9.20-9.fc25, 9.20-10.fc26
mupdf - addressed in versions 1.10a-6.fc25, 1.10a-6.fc26, 1.10a-7.fc25
ghostscript - addressed in versions 9.20-9.fc24, 9.20-9.fc25, 9.20-10.fc26
External References
Related Security Bulletins
- Ubuntu update for jbig2dec
- Gentoo update for jbig2dec
- Debian update for jbig2dec
- Fedora 26 update for ghostscript
- Fedora 25 update for ghostscript
- Fedora 24 update for ghostscript
- Fedora 25 update for jbig2dec
- Fedora 26 update for jbig2dec
- Fedora 26 update for mupdf
- Fedora 25 update for mupdf
- Fedora EPEL 7 update for jbig2dec
- Fedora 25 update for mupdf