MuPDF 'xps _ parse_color () 'function Stack Buffer Overflow Vulnerability
Release date:
Updated on:
Affected Systems:
MuPDF, MuPDF 1.3
Description:
--------------------------------------------------------------------------------
Bugtraq id: 65036
MuPDF is a lightweight PDF and XPS reader.
The stack buffer overflow vulnerability exists in the implementation of the 'xps _ parse_color () 'function in MuPDF 1.3 and earlier versions. Attackers can exploit this vulnerability to execute arbitrary code in the application context.
<* Source: Jean-Jamil Khalife
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
MuPDF
-----
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://mupdf.com/