Bug 1075936 - (CVE-2018-5686) VUL-0: CVE-2018-5686: mupdf: In MuPDF 1.12.0, there is an infinite loop vulnerability and application hang inthe pdf_parse_array function (pdf/pdf-parse.c) because EOF is not considered.Remote attackers could leverage this vulnerability to cause
(CVE-2018-5686)
VUL-0: CVE-2018-5686: mupdf: In MuPDF 1.12.0, there is an infinite loop vulne...
Status: RESOLVED FIXED
Classification: openSUSE
Product: openSUSE Distribution
Classification: openSUSE
Component: Other
Leap 42.3
Other Other
: P3 - Medium : Normal (vote)
: ---
Assigned To: Ismail Dönmez
Security Team bot
https://smash.suse.de/issue/198274/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2018-01-15 08:40 UTC by Marcus Meissner
Modified: 2018-01-25 23:41 UTC (History)
0 users

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Marcus Meissner 2018-01-15 08:40:13 UTC
CVE-2018-5686

In MuPDF 1.12.0, there is an infinite loop vulnerability and application hang in
the pdf_parse_array function (pdf/pdf-parse.c) because EOF is not considered.
Remote attackers could leverage this vulnerability to cause a denial of service
via a crafted pdf file.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-5686
https://bugs.ghostscript.com/show_bug.cgi?id=698860
Comment 1 Swamp Workflow Management 2018-01-22 13:00:20 UTC
This is an autogenerated message for OBS integration:
This bug (1075936) was mentioned in
https://build.opensuse.org/request/show/568127 Factory / mupdf
https://build.opensuse.org/request/show/568128 42.2 / mupdf
https://build.opensuse.org/request/show/568129 42.3 / mupdf
Comment 2 Swamp Workflow Management 2018-01-23 10:50:06 UTC
This is an autogenerated message for OBS integration:
This bug (1075936) was mentioned in
https://build.opensuse.org/request/show/568522 42.2 / mupdf
https://build.opensuse.org/request/show/568523 42.3 / mupdf
Comment 3 Swamp Workflow Management 2018-01-25 08:40:14 UTC
This is an autogenerated message for OBS integration:
This bug (1075936) was mentioned in
https://build.opensuse.org/request/show/569433 Factory / mupdf
Comment 4 Andreas Stieger 2018-01-25 19:15:49 UTC
done
Comment 5 Swamp Workflow Management 2018-01-25 23:09:21 UTC
openSUSE-SU-2018:0227-1: An update that fixes 5 vulnerabilities is now available.

Category: security (moderate)
Bug References: 1063413,1064027,1074116,1075936,1077161
CVE References: CVE-2017-15369,CVE-2017-15587,CVE-2017-17858,CVE-2017-17866,CVE-2018-5686
Sources used:
openSUSE Leap 42.3 (src):    mupdf-1.12.0-23.1
openSUSE Leap 42.2 (src):    mupdf-1.12.0-13.10.1