Release date:
Updated on:
Affected Systems:
MuPDF
Description:
--------------------------------------------------------------------------------
Cve id: CVE-2011-0341
Mozilla Firefox is a free open source browser applicable to Windows, Linux, and MacOS X platforms.
The MuPDF plug-in of Firefox has a buffer overflow vulnerability. Malicious users can exploit this vulnerability to control their systems.
This vulnerability is caused by the "register into _onmouse ()" function in apps/mozilla/cmd_main.c. By enticing users to browse a specially crafted website, stack buffer overflow occurs.
<* Source: Stefan Cornelius
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
MuPDF
-----
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://ccxvii.net/fitz/