Bugzilla – Bug 863975
VUL-0: CVE-2014-2013: mupdf: stack-based duffer overflow in xps_parse_color()
Last modified: 2014-03-03 20:26:10 UTC
Via OSS:12131 A stack-based duffer overflow was found inside the xps_parse_color() function of mupdf. This affects only openSUSE:13.1 and Factory. References: http://bugs.ghostscript.com/show_bug.cgi?id=694957 http://git.ghostscript.com/?p=mupdf.git;a=commitdiff;h=60dabde18d7fe12b19da8b509bdfee9cc886aafc https://bugzilla.redhat.com/show_bug.cgi?id=1056699 http://comments.gmane.org/gmane.comp.security.oss.general/12131
Who has set me as maintainer of mupdf? I've no time to handle this and I've never ever touched the source code of mupdf.
(In reply to comment #1) > Who has set me as maintainer of mupdf? I've no time to handle this and I've > never ever touched the source code of mupdf. I think you're the project maintainer of Publishing. You can hand over maintainership to me, I've just submitted a fix and apparently I'm the only one caring about it and de-facto maintainer anyway.
Guido, great, just set yourself as bugowner in that package. osc bugowner -s $your_account Publishing mupdf thanks a lot!
(In reply to comment #5) > Guido, great, just set yourself as bugowner in that package. I don't have the necessary permissions, you'll have to do that for me.
Werner, can you grant Guido maintainer rights there? The command would work anyway though, since it just creates a set_bugowner request when you have no maintainer rights ...
bugbot adjusting priority
This is an autogenerated message for OBS integration: This bug (863975) was mentioned in https://build.opensuse.org/request/show/222432 13.1 / mupdf
This is an autogenerated message for OBS integration: This bug (863975) was mentioned in https://build.opensuse.org/request/show/222656 Factory / mupdf
This is CVE-2014-2013 now.
This is an autogenerated message for OBS integration: This bug (863975) was mentioned in https://build.opensuse.org/request/show/223162 13.1 / mupdf
released
openSUSE-SU-2014:0309-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 863975 CVE References: CVE-2014-2013 Sources used: openSUSE 13.1 (src): mupdf-1.2-5.4.1