9.3
CVSSv2

CVE-2012-6535

Published: 02/12/2013 Updated: 24/01/2014
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

DjVuLibre prior to 3.5.25.3, as used in Evince, Sumatra PDF Reader, VuDroid, and other products, allows remote malicious users to execute arbitrary code or cause a denial of service (memory corruption) via a crafted DjVu (aka .djv) file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

djvulibre project djvulibre 3.5.21

djvulibre project djvulibre 3.5.20

djvulibre project djvulibre 3.5.13

djvulibre project djvulibre 3.5.12

djvulibre project djvulibre 3.5.4

djvulibre project djvulibre 3.5.3

djvulibre project djvulibre

djvulibre project djvulibre 3.5.24

djvulibre project djvulibre 3.5.17

djvulibre project djvulibre 3.5.16

djvulibre project djvulibre 3.5.9

djvulibre project djvulibre 3.5.8

djvulibre project djvulibre 3.5.23

djvulibre project djvulibre 3.5.22

djvulibre project djvulibre 3.5.15

djvulibre project djvulibre 3.5.14

djvulibre project djvulibre 3.5.7

djvulibre project djvulibre 3.5.6

djvulibre project djvulibre 3.5.5

djvulibre project djvulibre 3.5.19

djvulibre project djvulibre 3.5.18

djvulibre project djvulibre 3.5.11

djvulibre project djvulibre 3.5.10

djvulibre project djvulibre 3.5.2

djvulibre project djvulibre 3.5.1

Vendor Advisories

DjVuLibre could be made to crash or run programs as your login if it opened a specially crafted file ...
It was discovered that djvulibre, the Open Source DjVu implementation project, can be crashed or possibly make it execute arbitrary code when processing a specially crafted djvu file For the oldstable distribution (squeeze), this problem has been fixed in version 3523-3+squeeze1 This problem has been fixed before the release of the stable distr ...