605
VMScore

CVE-2017-17858

Published: 22/01/2018 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Heap-based buffer overflow in the ensure_solid_xref function in pdf/pdf-xref.c in Artifex MuPDF 1.12.0 allows a remote malicious user to potentially execute arbitrary code via a crafted PDF file, because xref subsection object numbers are unrestricted.

Vulnerable Product Search on Vulmon Subscribe to Product

artifex mupdf 1.12.0

Vendor Advisories

Heap-based buffer overflow in the ensure_solid_xref function in pdf/pdf-xrefc in Artifex MuPDF 1120 allows an attacker to potentially execute arbitrary code via a crafted PDF file, because xref subsection object numbers are unrestricted ...

Github Repositories

Publicly disclosed vulnerabilities I discovered in open source software

Security Advisories Upstream (libssh2) Security Advisory - Using SSH_MSG_KEXINIT data unbounded (CVE-2015-1782) Upstream (libssh) Security Advisory - Possible double free on a dangling pointer with crafted kexinit packet (CVE-2015-3146) MZET-ADV-2017-01 - Multiple memory corruption issues in Artifex MuPDF ver 1120 (CVE-2017-17858)