PT-2021-21584 · Mupdf+3 · Mupdf+3
Xuwei Liu
·
Published
2021-07-21
·
Updated
2025-10-16
·
CVE-2021-37220
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
MuPDF versions prior to 1.18.2
Description
The issue arises from an out-of-bounds write in the cached color converter, which fails to properly consider the maximum key size of a hash table. This can be observed with crafted "mutool draw" input.
Recommendations
For MuPDF versions prior to 1.18.2, update to version 1.18.2 or later to resolve the issue.
Exploit
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Linuxmint
Mupdf
Ubuntu