Debian Security Advisory
DSA-2844-1 djvulibre -- arbitrary code execution
- Date Reported:
- 15 Jan 2014
- Affected Packages:
- djvulibre
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2012-6535.
- More information:
-
It was discovered that djvulibre, the Open Source DjVu implementation project, can be crashed or possibly make it execute arbitrary code when processing a specially crafted djvu file.
For the oldstable distribution (squeeze), this problem has been fixed in version 3.5.23-3+squeeze1.
This problem has been fixed before the release of the stable distribution (wheezy), therefore it is not affected.
We recommend that you upgrade your djvulibre packages.