Debian alert DLA-4278-1 (mupdf)
From: | Chris Lamb <lamby@debian.org> | |
To: | debian-lts-announce@lists.debian.org | |
Subject: | [SECURITY] [DLA 4278-1] mupdf security update | |
Date: | Fri, 22 Aug 2025 09:33:10 -0700 | |
Message-ID: | <175587932897.266014.6122953543599648365@copycat> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4278-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Chris Lamb August 22, 2025 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : mupdf Version : 1.17.0+ds1-2+deb11u1 CVE ID : CVE-2020-21896 It was discovered that there was a potential use after free vulnerability in mupdf, a lightweight PDF viewer. This could have allowed remote attackers to cause a denial of service attack when opening a maliciously-crafted PDF file. For Debian 11 bullseye, this problem has been fixed in version 1.17.0+ds1-2+deb11u1. We recommend that you upgrade your mupdf packages. For the detailed security status of mupdf please refer to its security tracker page at: https://security-tracker.debian.org/tracker/mupdf Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEwv5L0nHBObhsUz5GHpU+J9QxHlgFAmiol58ACgkQHpU+J9Qx HljuIQ/+PdVpyN9GnJbM7/iCpAkyito1Qe7punb2a006p8BrGdbJsVpSx2am2IwJ gUUdAG9Docp26bkLKkgUlQwrZ4S/JG9kC7iDo9svhcYIJWGLVKcRSTOgrOKhVbUp HFL3QQVplgl5nO9lDqV42R0vm92Ic9df5wm9iAbI5LaRa2UnHaiArJVQavMnMNIp i7CKQl6ITp671ZqeOcAexsjWDp9ioyiprz820PhLN7C3yfvbA9RfqksSebPmTWaF JSXpHORB9EORo7nNUayI4tyf0GsQcw1Dt0IsMdAPE4sYjfI/+JKMod0X71FddLuZ eDdLNSzgFR/vqVVCFL4dZKlGtO/AFDQ3nCrkvnDQyxFd+se6QcGbXtA6lcvSvuze seeCf+0vFb/Dd0H0R9iYjh39P/rz6+QO1W4o9FeYkQAXsmr4OnvnAOwpxQWy0YVm RDRWveO25wq17U/JDeYkmYV7EOepes+aS7thiStA7VA2GAzG5nrTcFPD24BY9vKj wmLRnIhA/M6/bs+PWE8IsU0Fn1ty3+92u9t3QKkAsaoUwLqeF0BlLBpIJ8gsvzL1 HE6XRYH9chLTmz86SjPL2mKB/vun8YCtj+vh5cIg0TO+wSpUIswuSQFYAQFlieG2 J3ZPMsERpf9uMeT7iax73+3qGGqUU+d4pkhwiXVfgbOkGJYXtfQ= =wiNT -----END PGP SIGNATURE-----