4.3
CVSSv2

CVE-2018-16647

Published: 06/09/2018 Updated: 26/07/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

In Artifex MuPDF 1.13.0, the pdf_get_xref_entry function in pdf/pdf-xref.c allows remote malicious users to cause a denial of service (segmentation fault in fz_write_data in fitz/output.c) via a crafted pdf file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

artifex mupdf 1.13.0

Vendor Advisories

Debian Bug report logs - #924351 CVE-2018-16647 CVE-2018-16648 Package: mupdf; Maintainer for mupdf is Kan-Ru Chen (陳侃如) <koster@debianorg>; Source for mupdf is src:mupdf (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Mon, 11 Mar 2019 21:51:01 UTC Severity: grave Tags: fixed-upst ...