|
|
Subscribe / Log in / New account

Debian alert DLA-2589-1 (mupdf)

From:  Utkarsh Gupta <utkarsh@debian.org>
To:  debian-lts-announce@lists.debian.org
Subject:  [SECURITY] [DLA 2589-1] mupdf security update
Date:  Fri, 12 Mar 2021 00:19:58 +0530
Message-ID:   <CAPP0f94bSwDQZ6JTnMii3uKdnQwSGD21zdiLGHL6GB_zyr7B1Q@mail.gmail.com>

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ----------------------------------------------------------------------- Debian LTS Advisory DLA-2589-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Utkarsh Gupta March 12, 2021 https://wiki.debian.org/LTS - ----------------------------------------------------------------------- Package : mupdf Version : 1.9a+ds1-4+deb9u6 CVE ID : CVE-2020-26519 CVE-2021-3407 Debian Bug : 971595 983684 CVE-2020-26519 A heap-based buffer overflow flaw was discovered in MuPDF, a lightweight PDF viewer, which may result in denial of service or the execution of arbitrary code if malformed documents are opened. CVE-2021-3407 A double free of object during linearization was discovered in MuPDF, a lightweight PDF viewer, which may lead to memory corruption and other potential consequences. For Debian 9 stretch, these problems have been fixed in version 1.9a+ds1-4+deb9u6. We recommend that you upgrade your mupdf packages. For the detailed security status of mupdf please refer to its security tracker page at: https://security-tracker.debian.org/tracker/mupdf Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEbJ0QSEqa5Mw4X3xxgj6WdgbDS5YFAmBKYxQACgkQgj6WdgbD S5bPgw//bdIzz7/RBDxogXu+rfwOSMOVTR2dzs25GLA5RZ34niLAnvuP10oXzb6Q pwUTDrdbtsyP/tNiZJMAYT32bQY3n3gcj1ykmm8NcJ0BQ91QtjFDz8vpeb02R1Hn VCrdVYiLlveSPMbH7icnfjbWYe0FG66sqlYL1td+ft8BgMCqjV6IgtFJX8ZbNqPw kfwGjjDeAvMJlHmT4t8L6OvwRTTP2mDIjv85+vysCUiUzMzbco2eIAQbCoppsyMX 4PmEZpS3pRVk4K/2piV1C3Nz+SC/FJd1JgFN8R+UhB64wg78kBw+Th3I4v7LgcaV mtszF/drv3zZ743bwq2IaOIhbIs6VuLpj2BXgsSTPyRsS5BKhSajTNeMjbv5vMYU XJTEHLt/s2eOOOQHyQZ07p/F3mAswkBtgtAke+cW1q0NYQ/IR5HSGL/hC+7prKju sg30o2tnMaJKKkpeKvM+qKq/4eXcD8A9GEVSPUxBjV8kpKAF3eXCVYzJai4oJQdu k1vKmMA6eV0NybEb36vRy3fZ9ceP68MWIH3Y6D5tUN3J1gsLhpN2iHpT6s2SoPHF h5IRbo7gZZUnZeUtUC9Itw6o4uTgslGi8d5hICJEAcT/B8i/H5qT4tQp4Tf4oNHG XwlH36psH4FgLmHw3W8OA6UJASZlgf4+3CR1pL8MkfgmzibtWFw= =/5a6 -----END PGP SIGNATURE-----


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds