Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 803305 (CVE-2021-37220, CVE-2021-4216) - <app-text/mupdf-1.20.0: multiple vulnerabilities
Summary: <app-text/mupdf-1.20.0: multiple vulnerabilities
Status: IN_PROGRESS
Alias: CVE-2021-37220, CVE-2021-4216
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL: https://bugs.ghostscript.com/show_bug...
Whiteboard: B2 [glsa?]
Keywords:
Depends on:
Blocks:
 
Reported: 2021-07-22 01:51 UTC by John Helmert III
Modified: 2023-10-23 04:58 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-07-22 01:51:31 UTC
CVE-2021-37220:

MuPDF through 1.18.1 has an out-of-bounds write because the cached color converter does not properly consider the maximum key size of a hash table. This can, for example, be seen with crafted "mutool draw" input.

Unreleased patch: https://git.ghostscript.com/?p=mupdf.git;h=f5712c9949d026e4b891b25837edd2edc166151f
Comment 1 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2021-07-22 06:15:09 UTC
Asked upstream about versioning given I don't know if 1.18.1 is a proper release or not. Trying to avoid adding just this patch then ending up stabling something else given it likely has security related fixes in it, in short succession.
Comment 2 NATTkA bot gentoo-dev 2021-07-29 17:20:39 UTC Comment hidden (obsolete)
Comment 3 NATTkA bot gentoo-dev 2021-07-29 17:28:44 UTC Comment hidden (obsolete)
Comment 4 NATTkA bot gentoo-dev 2021-07-29 17:36:41 UTC Comment hidden (obsolete)
Comment 5 NATTkA bot gentoo-dev 2021-07-29 17:44:44 UTC Comment hidden (obsolete)
Comment 6 NATTkA bot gentoo-dev 2021-07-29 17:52:48 UTC Comment hidden (obsolete)
Comment 7 NATTkA bot gentoo-dev 2021-07-29 17:56:43 UTC Comment hidden (obsolete)
Comment 8 NATTkA bot gentoo-dev 2021-07-29 18:00:43 UTC Comment hidden (obsolete)
Comment 9 NATTkA bot gentoo-dev 2021-07-29 18:09:00 UTC
Package list is empty or all packages have requested keywords.
Comment 10 Niklāvs Koļesņikovs 2022-02-27 16:13:18 UTC
Version 1.19.0 is in tree and stable keyworded. There is also 1.18.0-r4 for which I was not able to quickly determine if it contains the fix for this particular CVE or not.
Comment 11 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-08-26 19:24:51 UTC
CVE-2021-4216 (https://bugs.ghostscript.com/show_bug.cgi?id=704834):

A Floating point exception (division-by-zero) flaw was found in Mupdf for zero width pages in muraster.c. It is fixed in Mupdf-1.20.0-rc1 upstream.

Patch, in 1.20.0: https://github.com/ArtifexSoftware/mupdf/commit/22c47acbd52949421f8c7cb46ea1556827d0fcbf
Comment 12 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-08-26 19:27:03 UTC
(In reply to Sam James from comment #1)
> Asked upstream about versioning given I don't know if 1.18.1 is a proper
> release or not. Trying to avoid adding just this patch then ending up
> stabling something else given it likely has security related fixes in it, in
> short succession.

In any case it's definitely in 1.19.0
Comment 13 Hans de Graaff gentoo-dev Security 2023-10-08 08:10:02 UTC
Ping. Please clean up the vulnerable version 1.19.1. It looks like this also requires app-text/zathura-pdf-mupdf-0.3.8-r2 to be removed.
Comment 14 Larry the Git Cow gentoo-dev 2023-10-22 14:50:15 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=8dc589bb73695e2b430fefd16f80669c42d2d736

commit 8dc589bb73695e2b430fefd16f80669c42d2d736
Author:     Joonas Niilola <juippis@gentoo.org>
AuthorDate: 2023-10-22 14:49:48 +0000
Commit:     Joonas Niilola <juippis@gentoo.org>
CommitDate: 2023-10-22 14:49:48 +0000

    app-text/mupdf: drop 1.19.1
    
    Bug: https://bugs.gentoo.org/803305
    Signed-off-by: Joonas Niilola <juippis@gentoo.org>

 app-text/mupdf/Manifest            |   1 -
 app-text/mupdf/mupdf-1.19.1.ebuild | 153 -------------------------------------
 2 files changed, 154 deletions(-)