CVE-2021-3407

Name
CVE-2021-3407
Description
A flaw was found in mupdf 1.18.0. Double free of object during linearization may lead to memory corruption and other potential consequences.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Patch http://git.ghostscript.com/?p=mupdf.git;h=cee7cefc610d42fd383b3c80c12cbc675443176a
Mailing List https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/M44PNYCBL33OD7GC75XNE6CDS4VSGVWO/
Mailing List https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LCADE3VSPWCGTE5BV4KL273R5VK3GDKM/
mailing-list https://lists.debian.org/debian-lts-announce/2021/03/msg00012.html
Mailing List https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZLC6MPH7YS6JPU427XOFRLF3KKZQUZJN/
vendor-advisory https://security.gentoo.org/glsa/202105-30
MISC http://git.ghostscript.com/?p=mupdf.git%3Bh=cee7cefc610d42fd383b3c80c12cbc675443176a
vendor-advisory https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LCADE3VSPWCGTE5BV4KL273R5VK3GDKM/
vendor-advisory https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M44PNYCBL33OD7GC75XNE6CDS4VSGVWO/
vendor-advisory https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZLC6MPH7YS6JPU427XOFRLF3KKZQUZJN/
https://bugs.ghostscript.com/show_bug.cgi?id=703366

Match rules

CPE URI Source package Min version Max version
mupdf == mupdf 1.18.0 == mupdf 1.18.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
mupdf edge-community 1.18.0-r2 Daniel Sabogal <dsabogalcc@gmail.com> fixed
mupdf edge-community 1.18.0-r1 Daniel Sabogal <dsabogalcc@gmail.com> fixed
mupdf 3.22-community 1.18.0-r1 None fixed
mupdf 3.21-community 1.18.0-r1 None fixed
mupdf 3.20-community 1.18.0-r1 None fixed
mupdf 3.19-community 1.18.0-r1 None fixed
mupdf 3.18-community 1.18.0-r1 None fixed
mupdf 3.17-community 1.18.0-r1 None fixed