PT-2021-21584 · Mupdf+3 · Mupdf+3

Xuwei Liu

·

Published

2021-07-21

·

Updated

2025-10-16

·

CVE-2021-37220

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions MuPDF versions prior to 1.18.2
Description The issue arises from an out-of-bounds write in the cached color converter, which fails to properly consider the maximum key size of a hash table. This can be observed with crafted "mutool draw" input.
Recommendations For MuPDF versions prior to 1.18.2, update to version 1.18.2 or later to resolve the issue.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-17298
ALT-PU-2024-17458
ALT-PU-2025-1462
ALT-PU-2025-5278
CVE-2021-37220
USN-7825-1

Affected Products

Alt Linux
Linuxmint
Mupdf
Ubuntu