PT-2018-9803 · Artifex+2 · Mupdf+2

Traceprobe

·

Published

2018-04-22

·

Updated

2025-10-16

·

CVE-2018-10289

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: MuPDF version 1.13.0
Description: The issue is related to an infinite loop in the fz skip space function of the pdf/pdf-xref.c file. This could allow a remote adversary to cause a denial of service via a crafted pdf file.
Recommendations: For MuPDF version 1.13.0, consider disabling the fz skip space function as a temporary workaround until a patch is available.

Exploit

Fix

DoS

Infinite Loop

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3475
ALT-PU-2020-3484
ALT-PU-2024-9899
CVE-2018-10289
DLA-2765-1
USN-7825-1

Affected Products

Alt Linux
Linuxmint
Mupdf