PT-2017-15056 · Artifex+1 · Mupdf+1

Ziqiang Gu

·

Published

2017-12-23

·

Updated

2019-03-11

·

CVE-2017-17866

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Artifex MuPDF versions prior to 1.12.0
Description The issue arises from the mishandling of certain length changes during a repair operation that occurs simultaneously with a clean operation in pdf/pdf-write.c. This can be exploited by remote attackers using a crafted PDF document, potentially leading to a denial of service through a buffer overflow and application crash, or possibly other unspecified impacts.
Recommendations For versions prior to 1.12.0, update to version 1.12.0 or later to resolve the issue.

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2415
CVE-2017-17866
DSA-4334-1

Affected Products

Alt Linux
Mupdf