Bug 990195 (CVE-2016-6265) - VUL-1: CVE-2016-6265: mupdf: use-after-free
Summary: VUL-1: CVE-2016-6265: mupdf: use-after-free
Status: RESOLVED FIXED
Alias: CVE-2016-6265
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other openSUSE 42.1
: P5 - None : Normal
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/171213/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2016-07-22 08:35 UTC by Andreas Stieger
Modified: 2016-08-01 03:11 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Andreas Stieger 2016-07-22 08:35:31 UTC
openSUSE only. No upstream patch available.
Comment 2 Dr. Werner Fink 2016-07-22 08:55:26 UTC
Not maintainer not bugowner of mupdf
Comment 3 Ismail Dönmez 2016-07-22 11:38:10 UTC
Submitted fixes to Leap 42.1, 42.2 and Tumbleweed.
Comment 4 Bernhard Wiedemann 2016-07-22 12:01:13 UTC
This is an autogenerated message for OBS integration:
This bug (990195) was mentioned in
https://build.opensuse.org/request/show/412765 Factory / mupdf
https://build.opensuse.org/request/show/412769 42.1 / mupdf
https://build.opensuse.org/request/show/412770 42.2 / mupdf
Comment 5 Andreas Stieger 2016-07-23 06:20:10 UTC
13.2 also needs a fix
Comment 6 Bernhard Wiedemann 2016-07-23 08:01:12 UTC
This is an autogenerated message for OBS integration:
This bug (990195) was mentioned in
https://build.opensuse.org/request/show/414564 13.2 / mupdf
Comment 7 Andreas Stieger 2016-07-23 08:40:26 UTC
Thank you for your submissions Ismail. We'll do the rest.
Comment 8 Andreas Stieger 2016-07-31 23:12:21 UTC
releasing update
Comment 9 Swamp Workflow Management 2016-08-01 03:11:40 UTC
openSUSE-SU-2016:1926-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 990195
CVE References: CVE-2016-6265
Sources used:
openSUSE Leap 42.1 (src):    mupdf-1.7a-7.1
openSUSE 13.2 (src):    mupdf-1.5-2.3.1