DSA-4152 mupdf – security update

Two vulnerabilities were discovered in MuPDF, a PDF, XPS, and e-bookviewer, which may result in denial of service or remote code execution.An attacker can craft a PDF document which, when opened in the victimhost, might consume vast amounts of memory, crash the program, or, insome cases, execute code in the context in which the application isrunning. More info: https://www.debian.org/security/2018/dsa-4152

DSA-4151 librelp – security update

Bas van Schaik and Kevin Backhouse discovered a stack-based bufferoverflow vulnerability in librelp, a library providing reliable eventlogging over the network, triggered while checking x509 certificatesfrom a peer. A remote attacker able to connect to rsyslog can takeadvantage of this flaw for remote code execution by sending a speciallycrafted x509 certificate. More info: https://www.debian.org/security/2018/dsa-4151
Translate »