PT-2019-6176 · Artifex+2 · Mupdf+2

Cylin

·

Published

2019-06-06

·

Updated

2024-07-31

·

CVE-2020-19609

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Artifex MuPDF versions prior to 1.18.0
Description The issue is related to a heap-based buffer over-write in the tiff expand colormap() function when parsing TIFF files. This allows attackers to cause a denial of service. The exploitation of this issue can be initiated remotely.
Recommendations For versions prior to 1.18.0, update to version 1.18.0 or later to resolve the issue. As a temporary workaround, consider disabling the tiff expand colormap() function until a patch is available.

Exploit

Fix

DoS

Memory Corruption

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3475
ALT-PU-2020-3484
ALT-PU-2024-9899
BDU:2022-01673
CVE-2020-19609
DLA-2765-1
OPENSUSE-SU-2021:1341-1
OPENSUSE-SU-2021_1341-1

Affected Products

Alt Linux
Mupdf
Suse