6.8
CVSSv2

CVE-2017-15587

Published: 18/10/2017 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

An integer overflow exists in pdf_read_new_xref_section in pdf/pdf-xref.c in Artifex MuPDF 1.11.

Vulnerable Product Search on Vulmon Subscribe to Product

artifex mupdf 1.11

Vendor Advisories

Debian Bug report logs - #877379 CVE-2017-14685 / CVE-2017-14686 / CVE-2017-14687 Package: mupdf; Maintainer for mupdf is Kan-Ru Chen (陳侃如) <koster@debianorg>; Source for mupdf is src:mupdf (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Sun, 1 Oct 2017 07:48:02 UTC Severity: gra ...
Debian Bug report logs - #879055 mupdf: CVE-2017-15587 Package: src:mupdf; Maintainer for src:mupdf is Kan-Ru Chen (陳侃如) <koster@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 18 Oct 2017 19:03:01 UTC Severity: grave Tags: patch, security, upstream Found in version mupdf/15-1 Fi ...
Multiple vulnerabilities have been found in MuPDF, a PDF file viewer, which may result in denial of service or the execution of arbitrary code CVE-2017-14685, CVE-2017-14686, and CVE-2017-14687 WangLin discovered that a crafted xps file can crash MuPDF and potentially execute arbitrary code in several ways, since the application m ...
An integer overflow leading to an out-of-bounds wrte has been found in mupdf <= 111 The parsing of a crafted PDF might allow an attacker to write controlled data to an arbitrary location in memory when performing truncated xref checks ...