PT-2020-14873 · Artifex+2 · Mupdf Library+2

Manh-Dung Nguyen

·

Published

2020-12-09

·

Updated

2024-07-31

·

CVE-2020-16600

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Artifex Software, Inc. MuPDF library versions 1.17.0-rc1 and earlier
Description A Use After Free issue exists when a valid page is followed by a page with invalid pixmap dimensions, causing bander - a static - to point to previously freed memory instead of a newband writer.
Recommendations For versions 1.17.0-rc1 and earlier, consider updating to a newer version to mitigate the risk, however, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use After Free

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3475
ALT-PU-2020-3484
ALT-PU-2024-9899
CVE-2020-16600
OPENSUSE-SU-2021:1341-1
OPENSUSE-SU-2021_1341-1

Affected Products

Alt Linux
Mupdf Library
Suse