6.8
CVSSv2

CVE-2012-5340

Published: 23/01/2020 Updated: 28/01/2020
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

SumatraPDF 2.1.1/MuPDF 1.0 allows remote malicious users to cause an Integer Overflow in the lex_number() function via a corrupt PDF file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sumatrapdfreader sumatrapdf 2.1.1

artifex mupdf 1.0

artifex mupdf 1.1

Exploits

Sumatra 211/MuPDF 10 Integer Overflow ======================================= There is an integer overflow on the MuPDF in the lex_number() function which can be triggered using a corrupt PDF file with ObjStm I'm attaching a file that reproduces the problem with the original unmodified file The ObjStm was modified to include big numbers Th ...