4.3
CVSSv2

CVE-2017-9216

Published: 24/05/2017 Updated: 02/11/2021
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

libjbig2dec.a in Artifex jbig2dec 0.13, as used in MuPDF and Ghostscript, has a NULL pointer dereference in the jbig2_huffman_get function in jbig2_huffman.c. For example, the jbig2dec utility will crash (segmentation fault) when parsing an invalid file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

artifex jbig2dec 0.13

debian debian linux 9.0

Vendor Advisories

Debian Bug report logs - #863279 jbig2dec: CVE-2017-9216: NULL pointer dereference in the jbig2_huffman_get function Package: src:jbig2dec; Maintainer for src:jbig2dec is Debian Printing Team <debian-printing@listsdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 24 May 2017 18:45:01 UTC ...
Several security issues were fixed in jbig2dec ...
libjbig2deca in Artifex jbig2dec 013, as used in MuPDF and Ghostscript, has a NULL pointer dereference in the jbig2_huffman_get function in jbig2_huffmanc For example, the jbig2dec utility will crash (segmentation fault) when parsing an invalid file ...