PT-2018-17624 · Artifex · Artifex Mupdf

Kim Gwan Yeong

·

Published

2018-02-02

·

Updated

2024-06-15

·

CVE-2018-6544

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Artifex MuPDF version 1.12.0
Description The issue allows remote attackers to cause a denial of service via a crafted PDF document. This is due to the pdf load obj stm function in pdf/pdf-xref.c referencing the object stream recursively, which can lead to running out of error stack.
Recommendations For Artifex MuPDF version 1.12.0, consider updating to a newer version that addresses this issue, as no specific fix is provided for this version. As a temporary workaround, consider restricting the processing of crafted PDF documents to minimize the risk of exploitation.

Exploit

Fix

DoS

Uncontrolled Recursion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-6544
DSA-4152-1
OPENSUSE-SU-2024:11068-1

Affected Products

Artifex Mupdf