Vulnerability Name:

CVE-2012-6535 (CCN-82950)

Assigned:2013-03-19
Published:2013-03-19
Updated:2014-01-24
Summary:DjVuLibre before 3.5.25.3, as used in Evince, Sumatra PDF Reader, VuDroid, and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted DjVu (aka .djv) file.
CVSS v3 Severity:7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C)
6.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
6.8 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P)
5.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-94
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2012-6535

Source: CCN
Type: DjVuLibre Web site
DjVuLibre

Source: CCN
Type: SA52697
DjVuLibre Text Encoding Conversion Memory Corruption Vulnerability

Source: CCN
Type: MSVR13-004
Vulnerability in DjVuLibre Could Allow Remote Code Execution

Source: MISC
Type: Vendor Advisory
http://technet.microsoft.com/security/msvr/msvr13-004

Source: DEBIAN
Type: UNKNOWN
DSA-2844

Source: CCN
Type: BID-58610
DjVuLibre '.djv' File CVE-2012-6535 Remote Memory Corruption Vulnerability

Source: UBUNTU
Type: UNKNOWN
USN-2056-1

Source: XF
Type: UNKNOWN
djvulibre-cve20126535-code-exec(82950)

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2012-6535

Vulnerable Configuration:Configuration 1:
  • cpe:/a:djvulibre_project:djvulibre:3.5.1:*:*:*:*:*:*:*
  • OR cpe:/a:djvulibre_project:djvulibre:3.5.2:*:*:*:*:*:*:*
  • OR cpe:/a:djvulibre_project:djvulibre:3.5.3:*:*:*:*:*:*:*
  • OR cpe:/a:djvulibre_project:djvulibre:3.5.4:*:*:*:*:*:*:*
  • OR cpe:/a:djvulibre_project:djvulibre:3.5.5:*:*:*:*:*:*:*
  • OR cpe:/a:djvulibre_project:djvulibre:3.5.6:*:*:*:*:*:*:*
  • OR cpe:/a:djvulibre_project:djvulibre:3.5.7:*:*:*:*:*:*:*
  • OR cpe:/a:djvulibre_project:djvulibre:3.5.8:*:*:*:*:*:*:*
  • OR cpe:/a:djvulibre_project:djvulibre:3.5.9:*:*:*:*:*:*:*
  • OR cpe:/a:djvulibre_project:djvulibre:3.5.10:*:*:*:*:*:*:*
  • OR cpe:/a:djvulibre_project:djvulibre:3.5.11:*:*:*:*:*:*:*
  • OR cpe:/a:djvulibre_project:djvulibre:3.5.12:*:*:*:*:*:*:*
  • OR cpe:/a:djvulibre_project:djvulibre:3.5.13:*:*:*:*:*:*:*
  • OR cpe:/a:djvulibre_project:djvulibre:3.5.14:*:*:*:*:*:*:*
  • OR cpe:/a:djvulibre_project:djvulibre:3.5.15:*:*:*:*:*:*:*
  • OR cpe:/a:djvulibre_project:djvulibre:3.5.16:*:*:*:*:*:*:*
  • OR cpe:/a:djvulibre_project:djvulibre:3.5.17:*:*:*:*:*:*:*
  • OR cpe:/a:djvulibre_project:djvulibre:3.5.18:*:*:*:*:*:*:*
  • OR cpe:/a:djvulibre_project:djvulibre:3.5.19:*:*:*:*:*:*:*
  • OR cpe:/a:djvulibre_project:djvulibre:3.5.20:*:*:*:*:*:*:*
  • OR cpe:/a:djvulibre_project:djvulibre:3.5.21:*:*:*:*:*:*:*
  • OR cpe:/a:djvulibre_project:djvulibre:3.5.22:*:*:*:*:*:*:*
  • OR cpe:/a:djvulibre_project:djvulibre:3.5.23:*:*:*:*:*:*:*
  • OR cpe:/a:djvulibre_project:djvulibre:3.5.24:*:*:*:*:*:*:*
  • OR cpe:/a:djvulibre_project:djvulibre:*:*:*:*:*:*:*:* (Version <= 3.5.25)

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.mitre.oval:def:20986
    P
    USN-2056-1 -- djvulibre vulnerability
    2014-06-30
    oval:org.mitre.oval:def:21512
    P
    DSA-2844-1 djvulibre - arbitrary code execution
    2014-06-23
    oval:com.ubuntu.precise:def:20126535000
    V
    CVE-2012-6535 on Ubuntu 12.04 LTS (precise) - medium.
    2013-12-02
    BACK
    djvulibre_project djvulibre 3.5.1
    djvulibre_project djvulibre 3.5.2
    djvulibre_project djvulibre 3.5.3
    djvulibre_project djvulibre 3.5.4
    djvulibre_project djvulibre 3.5.5
    djvulibre_project djvulibre 3.5.6
    djvulibre_project djvulibre 3.5.7
    djvulibre_project djvulibre 3.5.8
    djvulibre_project djvulibre 3.5.9
    djvulibre_project djvulibre 3.5.10
    djvulibre_project djvulibre 3.5.11
    djvulibre_project djvulibre 3.5.12
    djvulibre_project djvulibre 3.5.13
    djvulibre_project djvulibre 3.5.14
    djvulibre_project djvulibre 3.5.15
    djvulibre_project djvulibre 3.5.16
    djvulibre_project djvulibre 3.5.17
    djvulibre_project djvulibre 3.5.18
    djvulibre_project djvulibre 3.5.19
    djvulibre_project djvulibre 3.5.20
    djvulibre_project djvulibre 3.5.21
    djvulibre_project djvulibre 3.5.22
    djvulibre_project djvulibre 3.5.23
    djvulibre_project djvulibre 3.5.24
    djvulibre_project djvulibre *