Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.833117
Category:SuSE Local Security Checks
Title:openSUSE: Security Advisory for mupdf (openSUSE-SU-2022:10126-1)
Summary:The remote host is missing an update for the 'mupdf'; package(s) announced via the openSUSE-SU-2022:10126-1 advisory.
Description:Summary:
The remote host is missing an update for the 'mupdf'
package(s) announced via the openSUSE-SU-2022:10126-1 advisory.

Vulnerability Insight:
This update for mupdf fixes the following issues:
mupdf was updated to 1.20.3:

* return error, not success when unable to lock native device resource.

* Bug 705620: Start journal operation instead of pushing local xref.

* Ensure AndroidDrawDevice is destroyed, even upon exception.

* source/pdf/pdf-clean.c: fix segv from incorrect call to fz_drop_pixmap().

* Bug 705681: Enclose code in begin/end operation.

* Guard against SEGVs when calling archive functions with NULL archive.
mupdf was updated to 1.20.0 (boo#1202858, CVE-2021-4216):

* Experimental C# bindings

* Cross compilation should no longer need a host compiler

* Major additions to JNI bindings

* New API to edit outline

* New API to resolve and create links

* New API to toggle individual layers in PDF

* Layer panel in mupdf-gl

* Layer option in mutool draw

* New API to add a Javascript console

* Console panel in mupdf-gl

* Text search API extended to be able to distinguish between separate
search hits

* Command line tool improvements:

* all: Negative page numbers to index from the last page

* mutool draw: Add option to render document without text

* mutool draw and convert: Support DPI option in text and HTML output

* New hybrid HTML output format using 'scripts/pdftohtml' script:

* Graphics in a background image

* Text on top

* Improved WASM viewer demo

* Support high DPI screens

* Progressive loading

* Update to zlib 1.2.12 for security fix
mupdf was updated to 1.19.1:

* Updated zlib to 1.2.12 due to CVE-2018-25032

Affected Software/OS:
'mupdf' package(s) on openSUSE Backports SLE-15-SP4.

Solution:
Please install the updated package(s).

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2018-25032
https://github.com/madler/zlib/compare/v1.2.11...v1.2.12
https://security.netapp.com/advisory/ntap-20220526-0009/
https://support.apple.com/kb/HT213255
https://support.apple.com/kb/HT213256
https://support.apple.com/kb/HT213257
Debian Security Information: DSA-5111 (Google Search)
https://www.debian.org/security/2022/dsa-5111
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VOKNP2L734AEL47NRYGVZIKEFOUBQY5Y/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JZZPTWRYQULAOL3AW7RZJNVZ2UONXCV4/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NS2D2GFPFGOJUL4WQ3DUAY7HF4VWQ77F/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DF62MVMH3QUGMBDCB3DY2ERQ6EBHTADB/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DCZFIJBJTZ7CL5QXBFKTQ22Q26VINRUF/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XOKFMSNQ5D5WGMALBNBXU3GE442V74WU/
http://seclists.org/fulldisclosure/2022/May/38
http://seclists.org/fulldisclosure/2022/May/35
http://seclists.org/fulldisclosure/2022/May/33
https://security.gentoo.org/glsa/202210-42
https://github.com/madler/zlib/commit/5c44459c3b28a9bd3283aaceab7c615f8020c531
https://github.com/madler/zlib/issues/605
https://www.openwall.com/lists/oss-security/2022/03/24/1
https://www.openwall.com/lists/oss-security/2022/03/28/1
https://www.openwall.com/lists/oss-security/2022/03/28/3
https://www.oracle.com/security-alerts/cpujul2022.html
https://lists.debian.org/debian-lts-announce/2022/04/msg00000.html
https://lists.debian.org/debian-lts-announce/2022/05/msg00008.html
https://lists.debian.org/debian-lts-announce/2022/09/msg00023.html
http://www.openwall.com/lists/oss-security/2022/03/25/2
http://www.openwall.com/lists/oss-security/2022/03/26/1
Common Vulnerability Exposure (CVE) ID: CVE-2021-4216
https://bugs.ghostscript.com/show_bug.cgi?id=704834
https://github.com/ArtifexSoftware/mupdf/commit/22c47acbd52949421f8c7cb46ea1556827d0fcbf
CopyrightCopyright (C) 2024 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.