Bug#840957: mupdf: CVE-2016-8674: heap-use-after-free

2016-10-27 Thread Salvatore Bonaccorso
Hi, On Sun, Oct 16, 2016 at 02:51:06PM +0200, Salvatore Bonaccorso wrote: > Source: mupdf > Version: 1.5-1 > Severity: grave > Tags: security upstream patch > > Hi, > > the following vulnerability was published for mupdf. > > CVE-2016-8674[0]: > heap-use-after-free > > The issue is reproducibl

Bug#840957: mupdf: CVE-2016-8674: heap-use-after-free

2016-10-16 Thread Salvatore Bonaccorso
Source: mupdf Version: 1.5-1 Severity: grave Tags: security upstream patch Hi, the following vulnerability was published for mupdf. CVE-2016-8674[0]: heap-use-after-free The issue is reproducible with src:mupdf compiled with ASAN, and two reproducers are available on the two referenced bugs bel