PT-2019-18527 · Artifex · Artifex Mupdf
Erez
·
Published
2019-06-13
·
Updated
2024-09-11
·
CVE-2019-7321
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Artifex MuPDF version 1.14
Description
The issue is related to the usage of an uninitialized variable in the function
fz load jpeg, which can result in a heap overflow. This allows an attacker to execute arbitrary code.Recommendations
For Artifex MuPDF version 1.14, consider updating to a newer version that contains a fix for this issue, as using an uninitialized variable in the
fz load jpeg function poses a significant risk. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Use of Uninitialized Resource
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Artifex Mupdf