Summary: | MuPDF 1.0 Integer Overflow | ||
---|---|---|---|
Product: | MuPDF | Reporter: | Fernando M <xbefordx> |
Component: | mupdf | Assignee: | MuPDF bugs <mupdf-bugs> |
Status: | RESOLVED FIXED | ||
Severity: | normal | CC: | robin.watts, tor.andersson |
Priority: | P4 | ||
Version: | 1.0 | ||
Hardware: | PC | ||
OS: | Windows 7 | ||
Customer: | Word Size: | --- | |
Attachments: | Test case for this bug. |
Description
Fernando M
2012-10-09 01:56:18 UTC
Created attachment 8992 [details]
Test case for this bug.
ObjStm was modified to reproduce the integer overflow and write access violation.
CVE-2012-5340 was requested and assigned for this issue. So, what is required of us here? A rebuild of an up to date version for iOS? That would be perfect. I wasn't sure about reporting the issue but since some software maybe still using the previous library it's better to let them know it. I've already contacted the SumatraPDF author because the current stable version still uses MuPDF 1.0. I will wait some weeks before making the public announcement of the flaw. |