9.3

CVE-2012-6535

DjVuLibre before 3.5.25.3, as used in Evince, Sumatra PDF Reader, VuDroid, and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted DjVu (aka .djv) file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Djvulibre Project ≫ Djvulibre Version <= 3.5.25
Djvulibre Project ≫ Djvulibre Version 3.5.1
Djvulibre Project ≫ Djvulibre Version 3.5.2
Djvulibre Project ≫ Djvulibre Version 3.5.3
Djvulibre Project ≫ Djvulibre Version 3.5.4
Djvulibre Project ≫ Djvulibre Version 3.5.5
Djvulibre Project ≫ Djvulibre Version 3.5.6
Djvulibre Project ≫ Djvulibre Version 3.5.7
Djvulibre Project ≫ Djvulibre Version 3.5.8
Djvulibre Project ≫ Djvulibre Version 3.5.9
Djvulibre Project ≫ Djvulibre Version 3.5.10
Djvulibre Project ≫ Djvulibre Version 3.5.11
Djvulibre Project ≫ Djvulibre Version 3.5.12
Djvulibre Project ≫ Djvulibre Version 3.5.13
Djvulibre Project ≫ Djvulibre Version 3.5.14
Djvulibre Project ≫ Djvulibre Version 3.5.15
Djvulibre Project ≫ Djvulibre Version 3.5.16
Djvulibre Project ≫ Djvulibre Version 3.5.17
Djvulibre Project ≫ Djvulibre Version 3.5.18
Djvulibre Project ≫ Djvulibre Version 3.5.19
Djvulibre Project ≫ Djvulibre Version 3.5.20
Djvulibre Project ≫ Djvulibre Version 3.5.21
Djvulibre Project ≫ Djvulibre Version 3.5.22
Djvulibre Project ≫ Djvulibre Version 3.5.23
Djvulibre Project ≫ Djvulibre Version 3.5.24
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.64% 0.905
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

http://technet.microsoft.com/security/msvr/msvr13-004
Vendor Advisory
http://www.debian.org/security/2014/dsa-2844
http://www.ubuntu.com/usn/USN-2056-1