CVE-2012-6535

DjVuLibre before 3.5.25.3, as used in Evince, Sumatra PDF Reader, VuDroid, and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted DjVu (aka .djv) file.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 89%
VendorProductVersion
djvulibre_projectdjvulibre
𝑥
≤ 3.5.25
djvulibre_projectdjvulibre
3.5.1
djvulibre_projectdjvulibre
3.5.2
djvulibre_projectdjvulibre
3.5.3
djvulibre_projectdjvulibre
3.5.4
djvulibre_projectdjvulibre
3.5.5
djvulibre_projectdjvulibre
3.5.6
djvulibre_projectdjvulibre
3.5.7
djvulibre_projectdjvulibre
3.5.8
djvulibre_projectdjvulibre
3.5.9
djvulibre_projectdjvulibre
3.5.10
djvulibre_projectdjvulibre
3.5.11
djvulibre_projectdjvulibre
3.5.12
djvulibre_projectdjvulibre
3.5.13
djvulibre_projectdjvulibre
3.5.14
djvulibre_projectdjvulibre
3.5.15
djvulibre_projectdjvulibre
3.5.16
djvulibre_projectdjvulibre
3.5.17
djvulibre_projectdjvulibre
3.5.18
djvulibre_projectdjvulibre
3.5.19
djvulibre_projectdjvulibre
3.5.20
djvulibre_projectdjvulibre
3.5.21
djvulibre_projectdjvulibre
3.5.22
djvulibre_projectdjvulibre
3.5.23
djvulibre_projectdjvulibre
3.5.24
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
djvulibre
sid
3.5.28-2
fixed
trixie
3.5.28-2
fixed
bookworm
3.5.28-2
fixed
bullseye
3.5.28-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
djvulibre
saucy
not-affected
raring
not-affected
quantal
not-affected
precise
Fixed 3.5.24-9ubuntu0.1
released
lucid
ignored