PT-2013-1999 · None+1 · Sumatrapdf Reader+3

Jeremy Brown

·

Published

2013-12-02

·

Updated

2014-01-24

·

CVE-2012-6535

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions DjVuLibre versions prior to 3.5.25.3
Description The issue allows remote attackers to execute arbitrary code or cause a denial of service due to memory corruption via a crafted DjVu file. This affects products that use DjVuLibre, such as Evince, Sumatra PDF Reader, and VuDroid.
Recommendations For versions prior to 3.5.25.3, update to version 3.5.25.3 or later to resolve the issue.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-6535
DSA-2844-1

Affected Products

Djvulibre
Evince
Sumatrapdf Reader
Vudroid