Bugzilla – Bug 1216728
VUL-0: CVE-2023-31794: mupdf: infinite recursion in pdf_mark_list_push
Last modified: 2023-11-11 14:04:58 UTC
MuPDF v1.21.1 was discovered to contain an infinite recursion in the component pdf_mark_list_push. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PDF file. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-31794
Maintainer's email address doesn't exist anymore so I assigned to the second last person who submitted an update (Dirk). Fixing commit: https://github.com/ArtifexSoftware/mupdf/commit/c0015401693b58e2deb5d75c39f27bc1216e47c6 openSUSE:Factory is already fixed, but relevant for Backports.
This is an autogenerated message for OBS integration: This bug (1216728) was mentioned in https://build.opensuse.org/request/show/1123576 Backports:SLE-15-SP6 / mupdf
submitted to SP5 and SP6 backports
This is an autogenerated message for OBS integration: This bug (1216728) was mentioned in https://build.opensuse.org/request/show/1124038 Backports:SLE-15-SP5 / mupdf
openSUSE-SU-2023:0363-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1216728 CVE References: CVE-2023-31794 JIRA References: Sources used: openSUSE Backports SLE-15-SP5 (src): mupdf-1.21.1-bp155.3.3.1