Bug 2255928 (CVE-2023-51103, CVE-2023-51104, CVE-2023-51105, CVE-2023-51106, CVE-2023-51107) - CVE-2023-51107 CVE-2023-51106 CVE-2023-51105 CVE-2023-51104 CVE-2023-51103 mupdf: Multiple vulnerabilities
Summary: CVE-2023-51107 CVE-2023-51106 CVE-2023-51105 CVE-2023-51104 CVE-2023-51103 mu...
Keywords:
Status: NEW
Alias: CVE-2023-51103, CVE-2023-51104, CVE-2023-51105, CVE-2023-51106, CVE-2023-51107
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2255929
Blocks:
TreeView+ depends on / blocked
 
Reported: 2023-12-26 20:40 UTC by Patrick Del Bello
Modified: 2024-02-20 17:21 UTC (History)
1 user (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Patrick Del Bello 2023-12-26 20:40:47 UTC
CVE-2023-51107
A floating point exception (divide-by-zero) vulnerability was discovered in mupdf 1.23.4 in functon compute_color() of jquant2.c.

https://github.com/dongyuma/sox-defects/blob/main/mupdf-defects.md


CVE-2023-51106
A floating point exception (divide-by-zero) vulnerability was discovered in mupdf 1.23.4 in functon pnm_binary_read_image() of load-pnm.c.

https://github.com/dongyuma/sox-defects/blob/main/mupdf-defects.md

CVE-2023-51105
A floating point exception (divide-by-zero) vulnerability was discovered in mupdf 1.23.4 in function bmp_decompress_rle4() of load-bmp.c.

https://github.com/dongyuma/sox-defects/blob/main/mupdf-defects.md

CVE-2023-51104
A floating point exception (divide-by-zero) vulnerability was discovered in mupdf 1.23.4 in functon pnm_binary_read_image() of load-pnm.c line 527.

https://github.com/dongyuma/sox-defects/blob/main/mupdf-defects.md


CVE-2023-51103
A floating point exception (divide-by-zero) vulnerability was discovered in mupdf 1.23.4 in functon fz_new_pixmap_from_float_data() of pixmap.c.

https://github.com/dongyuma/sox-defects/blob/main/mupdf-defects.md

Comment 1 Patrick Del Bello 2023-12-26 20:40:59 UTC
Created mupdf tracking bugs for this issue:

Affects: fedora-all [bug 2255929]

Comment 2 Michael J Gruber 2023-12-26 20:58:13 UTC
None of those CVE links is accessible. As such, they provide no useful information.

Comment 3 Michael J Gruber 2024-02-20 17:21:06 UTC
OP does not seem to care about accessibility of CVE information, it seems.

In any case, publicly searchable CVEs give no information about the actual bug nor how to reproduce it nor the analysis, and the analysis has not been redone by the CVE reporter for 6 mupdf versions now, nor for upstream's extensive work beyond the latest release. If cannot confirm validity I will have to close the bug against mupdf accordingly.


Note You need to log in before you can comment on or make changes to this bug.