Upstream information

CVE-2017-9216 at MITRE

Description

libjbig2dec.a in Artifex jbig2dec 0.13, as used in MuPDF and Ghostscript, has a NULL pointer dereference in the jbig2_huffman_get function in jbig2_huffman.c. For example, the jbig2dec utility will crash (segmentation fault) when parsing an invalid file.

SUSE information

CVSS v2 Scores
  National Vulnerability Database SUSE
Base Score 4.30 4.30
Vector AV:N/AC:M/Au:N/C:N/I:N/A:P AV:N/AC:M/Au:N/C:N/I:N/A:P
Access Vector Network Network
Access Complexity Medium Medium
Authentication None None
Confidentiality Impact None None
Integrity Impact None None
Availability Impact Partial Partial
CVSS v3 Scores
  National Vulnerability Database SUSE
Base Score 6.5 5.3
Vector AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Access Vector Network Network
Access Complexity Low Low
Privileges Required None None
User Interaction Required None
Scope Unchanged Unchanged
Confidentiality Impact None None
Integrity Impact None None
Availability Impact High Low

This issue is currently rated as having moderate severity.

SUSE Bugzilla entry: 1040643 [NEW]

No SUSE Security Announcements cross referenced.