Bugzilla – Bug 1094634
VUL-1: CVE-2018-1000036: mupdf: memory leaks in the PDF parser
Last modified: 2020-01-16 14:00:12 UTC
rh#1582315 In MuPDF 1.12.0 and earlier, multiple memory leaks in the PDF parser allow an attacker to cause a denial of service (memory leak) via a crafted file. References: https://bugzilla.redhat.com/show_bug.cgi?id=1582315 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-1000036 http://people.canonical.com/~ubuntu-security/cve/2018/CVE-2018-1000036.html https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=5502
Fixed in openSUSE:Factory (version 1.13) already, still an issue for openSUSE:Leap:42.3.
Karol, was it fixed with a SUSE specific patch? AFAICS, and following https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=5502 the issue is still unadressed (although minor severity) not yet in 1.13.0.
This is automated batch bugzilla cleanup. The openSUSE 42.3 changed to end-of-life (EOL [1]) status. As such it is no longer maintained, which means that it will not receive any further security or bug fix updates. As a result we are closing this bug. If you can reproduce this bug against a currently maintained version of openSUSE (At this moment openSUSE Leap 15.1, 15.0 and Tumbleweed) please feel free to reopen this bug against that version (!you must update the "Version" component in the bug fields, do not just reopen please), or alternatively create a new ticket. Thank you for reporting this bug and we are sorry it could not be fixed during the lifetime of the release. [1] https://en.opensuse.org/Lifetime
15.0 and 15.1 still unfixed