Bugzilla – Bug 990195
VUL-1: CVE-2016-6265: mupdf: use-after-free
Last modified: 2016-08-01 03:11:40 UTC
http://seclists.org/oss-sec/2016/q3/127 A use-after free-issue was reported in MuPDF. Reproducer and report: http://bugs.ghostscript.com/show_bug.cgi?id=696941 References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-6265 http://seclists.org/oss-sec/2016/q3/127 http://people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-6265.html
openSUSE only. No upstream patch available.
Not maintainer not bugowner of mupdf
Submitted fixes to Leap 42.1, 42.2 and Tumbleweed.
This is an autogenerated message for OBS integration: This bug (990195) was mentioned in https://build.opensuse.org/request/show/412765 Factory / mupdf https://build.opensuse.org/request/show/412769 42.1 / mupdf https://build.opensuse.org/request/show/412770 42.2 / mupdf
13.2 also needs a fix
This is an autogenerated message for OBS integration: This bug (990195) was mentioned in https://build.opensuse.org/request/show/414564 13.2 / mupdf
Thank you for your submissions Ismail. We'll do the rest.
releasing update
openSUSE-SU-2016:1926-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 990195 CVE References: CVE-2016-6265 Sources used: openSUSE Leap 42.1 (src): mupdf-1.7a-7.1 openSUSE 13.2 (src): mupdf-1.5-2.3.1