PT-2023-11607 · Artifex+2 · Mupdf+2

Suhwan

·

Published

2023-08-22

·

Updated

2025-10-16

·

CVE-2020-21896

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Artifex Software MuPDF version 1.16.0
Description A Use After Free vulnerability in the svg dev text span as paths defs function in source/fitz/svg-device.c allows remote attackers to cause a denial of service via the opening of a crafted PDF file.
Recommendations For Artifex Software MuPDF version 1.16.0, consider disabling the svg dev text span as paths defs function until a patch is available to prevent exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Use After Free

Weakness Enumeration

Related Identifiers

CVE-2020-21896
DLA-4278-1
USN-7825-1

Affected Products

Debian
Linuxmint
Mupdf