PT-2023-11607 · Artifex+2 · Mupdf+2

Suhwan

·

Publicado

2023-08-22

·

Atualizado

2025-10-16

·

CVE-2020-21896

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Artifex Software MuPDF version 1.16.0
Description A Use After Free vulnerability in the svg dev text span as paths defs function in source/fitz/svg-device.c allows remote attackers to cause a denial of service via the opening of a crafted PDF file.
Recommendations For Artifex Software MuPDF version 1.16.0, consider disabling the svg dev text span as paths defs function until a patch is available to prevent exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2020-21896
DLA-4278-1
USN-7825-1

Produtos afetados

Debian
Linuxmint
Mupdf