PT-2019-17968 · Artifex · Artifex Mupdf

Zerokeeper

·

Published

2019-01-11

·

Updated

2024-09-11

·

CVE-2019-6130

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Artifex MuPDF version 1.14.0
Description The issue is related to a SEGV in the fz load page function of the fitz/document.c file. This problem arises from page-number mishandling in several files, including cbz/mucbz.c, cbz/muimg.c, and svg/svg-doc.c. The issue can be demonstrated using mutool.
Recommendations For Artifex MuPDF version 1.14.0, consider disabling the fz load page function as a temporary workaround until a patch is available. Restrict access to the affected files, including cbz/mucbz.c, cbz/muimg.c, and svg/svg-doc.c, to minimize the risk of exploitation.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2019-6130
DLA-1838-1
DLA-2289-1

Affected Products

Artifex Mupdf