Bug 1077161 - (CVE-2017-17858) VUL-0: CVE-2017-17858: Heap-based buffer overflow in the ensure_solid_xref function in pdf/pdf-xref.cin Artifex MuPDF 1.12.0 allows a remote attacker to potentially execute arbitrary code via a crafted PDF file, because xref subsection obj
(CVE-2017-17858)
VUL-0: CVE-2017-17858: Heap-based buffer overflow in the ensure_solid_xref fu...
Status: RESOLVED FIXED
Classification: openSUSE
Product: openSUSE Distribution
Classification: openSUSE
Component: Security
Leap 42.3
Other Other
: P3 - Medium : Normal (vote)
: ---
Assigned To: Ismail Dönmez
Security Team bot
https://smash.suse.de/issue/198756/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2018-01-23 08:53 UTC by Karol Babioch
Modified: 2018-01-25 23:40 UTC (History)
0 users

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Karol Babioch 2018-01-23 08:53:27 UTC
CVE-2017-17858

Heap-based buffer overflow in the ensure_solid_xref function in pdf/pdf-xref.c
in Artifex MuPDF 1.12.0 allows a remote attacker to potentially execute
arbitrary code via a crafted PDF file, because xref subsection object numbers
are unrestricted.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-17858
http://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-17858.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17858
https://github.com/mzet-/Security-Advisories/blob/master/mzet-adv-2017-01.md
https://bugs.ghostscript.com/show_bug.cgi?id=698819
http://git.ghostscript.com/?p=mupdf.git;a=commit;h=55c3f68d638ac1263a386e0aaa004bb6e8bde731
Comment 1 Karol Babioch 2018-01-23 09:15:14 UTC
I've applied the upstream patch and created a submit request: https://build.opensuse.org/request/show/568499
Comment 2 Swamp Workflow Management 2018-01-23 10:50:10 UTC
This is an autogenerated message for OBS integration:
This bug (1077161) was mentioned in
https://build.opensuse.org/request/show/568522 42.2 / mupdf
https://build.opensuse.org/request/show/568523 42.3 / mupdf
Comment 3 Swamp Workflow Management 2018-01-25 08:40:22 UTC
This is an autogenerated message for OBS integration:
This bug (1077161) was mentioned in
https://build.opensuse.org/request/show/569433 Factory / mupdf
Comment 4 Andreas Stieger 2018-01-25 19:15:47 UTC
done
Comment 5 Swamp Workflow Management 2018-01-25 23:09:29 UTC
openSUSE-SU-2018:0227-1: An update that fixes 5 vulnerabilities is now available.

Category: security (moderate)
Bug References: 1063413,1064027,1074116,1075936,1077161
CVE References: CVE-2017-15369,CVE-2017-15587,CVE-2017-17858,CVE-2017-17866,CVE-2018-5686
Sources used:
openSUSE Leap 42.3 (src):    mupdf-1.12.0-23.1
openSUSE Leap 42.2 (src):    mupdf-1.12.0-13.10.1