PT-2019-17969 · Artifex · Artifex Mupdf

Zerokeeper

·

Published

2019-01-11

·

Updated

2024-09-11

·

CVE-2019-6131

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Artifex MuPDF version 1.14.0
Description The issue is related to infinite recursion with stack consumption in the svg run use symbol, svg run element, and svg run use functions in the svg-run.c file. This can be demonstrated using mutool.
Recommendations For Artifex MuPDF version 1.14.0, consider disabling the svg run use symbol, svg run element, and svg run use functions as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Uncontrolled Recursion

Weakness Enumeration

Related Identifiers

CVE-2019-6131

Affected Products

Artifex Mupdf