| |
Vulnerability CVE-2012-6535
Published: 2013-12-02 Modified: 2013-12-03
Description: |
DjVuLibre before 3.5.25.3, as used in Evince, Sumatra PDF Reader, VuDroid, and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted DjVu (aka .djv) file. |
Type:
CWE-94 (Improper Control of Generation of Code ('Code Injection'))
CVSS2 => (AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS Base Score |
Impact Subscore |
Exploitability Subscore |
9.3/10 |
10/10 |
8.6/10 |
Exploit range |
Attack complexity |
Authentication |
Remote |
Medium |
No required |
Confidentiality impact |
Integrity impact |
Availability impact |
Complete |
Complete |
Complete |
References: |
http://www.ubuntu.com/usn/USN-2056-1
http://www.debian.org/security/2014/dsa-2844
http://technet.microsoft.com/security/msvr/msvr13-004
|
|
|
Copyright 2024, cxsecurity.com
|
|
|