Vulnerability Name:
CVE-2012-6535 (CCN-82950)
Assigned:
2013-03-19
Published:
2013-03-19
Updated:
2014-01-24
Summary:
DjVuLibre before 3.5.25.3, as used in Evince, Sumatra PDF Reader, VuDroid, and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted DjVu (aka .djv) file.
CVSS v3 Severity:
7.3 High
(CCN CVSS v3.1 Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
)
Exploitability Metrics:
Attack Vector (AV):
Network
Attack Complexity (AC):
Low
Privileges Required (PR):
None
User Interaction (UI):
None
Scope:
Scope (S):
Unchanged
Impact Metrics:
Confidentiality (C):
Low
Integrity (I):
Low
Availibility (A):
Low
CVSS v2 Severity:
9.3 High
(CVSS v2 Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C
)
6.9 Medium
(Temporal CVSS v2 Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
Medium
Authentication (Au):
None
Impact Metrics:
Confidentiality (C):
Complete
Integrity (I):
Complete
Availibility (A):
Complete
6.8 Medium
(CCN CVSS v2 Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P
)
5.0 Medium
(CCN Temporal CVSS v2 Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C
)
Exploitability Metrics:
Access Vector (AV):
Network
Access Complexity (AC):
Medium
Athentication (Au):
None
Impact Metrics:
Confidentiality (C):
Partial
Integrity (I):
Partial
Availibility (A):
Partial
Vulnerability Type:
CWE-94
Vulnerability Consequences:
Gain Access
References:
Source: MITRE
Type: CNA
CVE-2012-6535
Source: CCN
Type: DjVuLibre Web site
DjVuLibre
Source: CCN
Type: SA52697
DjVuLibre Text Encoding Conversion Memory Corruption Vulnerability
Source: CCN
Type: MSVR13-004
Vulnerability in DjVuLibre Could Allow Remote Code Execution
Source: MISC
Type: Vendor Advisory
http://technet.microsoft.com/security/msvr/msvr13-004
Source: DEBIAN
Type: UNKNOWN
DSA-2844
Source: CCN
Type: BID-58610
DjVuLibre '.djv' File CVE-2012-6535 Remote Memory Corruption Vulnerability
Source: UBUNTU
Type: UNKNOWN
USN-2056-1
Source: XF
Type: UNKNOWN
djvulibre-cve20126535-code-exec(82950)
Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2012-6535
Vulnerable Configuration:
Configuration 1
:
cpe:/a:djvulibre_project:djvulibre:3.5.1:*:*:*:*:*:*:*
OR
cpe:/a:djvulibre_project:djvulibre:3.5.2:*:*:*:*:*:*:*
OR
cpe:/a:djvulibre_project:djvulibre:3.5.3:*:*:*:*:*:*:*
OR
cpe:/a:djvulibre_project:djvulibre:3.5.4:*:*:*:*:*:*:*
OR
cpe:/a:djvulibre_project:djvulibre:3.5.5:*:*:*:*:*:*:*
OR
cpe:/a:djvulibre_project:djvulibre:3.5.6:*:*:*:*:*:*:*
OR
cpe:/a:djvulibre_project:djvulibre:3.5.7:*:*:*:*:*:*:*
OR
cpe:/a:djvulibre_project:djvulibre:3.5.8:*:*:*:*:*:*:*
OR
cpe:/a:djvulibre_project:djvulibre:3.5.9:*:*:*:*:*:*:*
OR
cpe:/a:djvulibre_project:djvulibre:3.5.10:*:*:*:*:*:*:*
OR
cpe:/a:djvulibre_project:djvulibre:3.5.11:*:*:*:*:*:*:*
OR
cpe:/a:djvulibre_project:djvulibre:3.5.12:*:*:*:*:*:*:*
OR
cpe:/a:djvulibre_project:djvulibre:3.5.13:*:*:*:*:*:*:*
OR
cpe:/a:djvulibre_project:djvulibre:3.5.14:*:*:*:*:*:*:*
OR
cpe:/a:djvulibre_project:djvulibre:3.5.15:*:*:*:*:*:*:*
OR
cpe:/a:djvulibre_project:djvulibre:3.5.16:*:*:*:*:*:*:*
OR
cpe:/a:djvulibre_project:djvulibre:3.5.17:*:*:*:*:*:*:*
OR
cpe:/a:djvulibre_project:djvulibre:3.5.18:*:*:*:*:*:*:*
OR
cpe:/a:djvulibre_project:djvulibre:3.5.19:*:*:*:*:*:*:*
OR
cpe:/a:djvulibre_project:djvulibre:3.5.20:*:*:*:*:*:*:*
OR
cpe:/a:djvulibre_project:djvulibre:3.5.21:*:*:*:*:*:*:*
OR
cpe:/a:djvulibre_project:djvulibre:3.5.22:*:*:*:*:*:*:*
OR
cpe:/a:djvulibre_project:djvulibre:3.5.23:*:*:*:*:*:*:*
OR
cpe:/a:djvulibre_project:djvulibre:3.5.24:*:*:*:*:*:*:*
OR
cpe:/a:djvulibre_project:djvulibre:*:*:*:*:*:*:*:*
(Version <= 3.5.25)
Denotes that component is vulnerable
Oval Definitions
Definition ID
Class
Title
Last Modified
oval:org.mitre.oval:def:20986
P
USN-2056-1 -- djvulibre vulnerability
2014-06-30
oval:org.mitre.oval:def:21512
P
DSA-2844-1 djvulibre - arbitrary code execution
2014-06-23
oval:com.ubuntu.precise:def:20126535000
V
CVE-2012-6535 on Ubuntu 12.04 LTS (precise) - medium.
2013-12-02
BACK
djvulibre_project
djvulibre 3.5.1
djvulibre_project
djvulibre 3.5.2
djvulibre_project
djvulibre 3.5.3
djvulibre_project
djvulibre 3.5.4
djvulibre_project
djvulibre 3.5.5
djvulibre_project
djvulibre 3.5.6
djvulibre_project
djvulibre 3.5.7
djvulibre_project
djvulibre 3.5.8
djvulibre_project
djvulibre 3.5.9
djvulibre_project
djvulibre 3.5.10
djvulibre_project
djvulibre 3.5.11
djvulibre_project
djvulibre 3.5.12
djvulibre_project
djvulibre 3.5.13
djvulibre_project
djvulibre 3.5.14
djvulibre_project
djvulibre 3.5.15
djvulibre_project
djvulibre 3.5.16
djvulibre_project
djvulibre 3.5.17
djvulibre_project
djvulibre 3.5.18
djvulibre_project
djvulibre 3.5.19
djvulibre_project
djvulibre 3.5.20
djvulibre_project
djvulibre 3.5.21
djvulibre_project
djvulibre 3.5.22
djvulibre_project
djvulibre 3.5.23
djvulibre_project
djvulibre 3.5.24
djvulibre_project
djvulibre *