5.5
CVSSv3

CVE-2018-5686

Published: 14/01/2018 Updated: 30/01/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

In MuPDF 1.12.0, there is an infinite loop vulnerability and application hang in the pdf_parse_array function (pdf/pdf-parse.c) because EOF is not considered. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted pdf file.

Vulnerable Product Search on Vulmon Subscribe to Product

artifex mupdf 1.12.0

debian debian linux 8.0

debian debian linux 9.0

Vendor Advisories

Multiple vulnerabilities were discovered in MuPDF, a PDF, XPS, and e-book viewer which could result in denial of service or the execution of arbitrary code if malformed documents are opened For the stable distribution (stretch), these problems have been fixed in version 19a+ds1-4+deb9u4 We recommend that you upgrade your mupdf packages For the ...
Debian Bug report logs - #887130 mupdf: CVE-2018-5686 Package: src:mupdf; Maintainer for src:mupdf is Kan-Ru Chen (陳侃如) <koster@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 14 Jan 2018 10:21:02 UTC Severity: important Tags: security, upstream Found in version mupdf/15-1 Fixed ...
Debian Bug report logs - #888464 mupdf: CVE-2018-6187: heap-based buffer overflow in pdf/pdf-writec:do_pdf_save_document() Package: src:mupdf; Maintainer for src:mupdf is Kan-Ru Chen (陳侃如) <koster@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 25 Jan 2018 23:21:01 UTC Severity: i ...
Debian Bug report logs - #888487 mupdf: CVE-2018-6192 Package: src:mupdf; Maintainer for src:mupdf is Kan-Ru Chen (陳侃如) <koster@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 26 Jan 2018 10:03:01 UTC Severity: important Tags: security, upstream Found in version mupdf/111+ds1-2 F ...
In MuPDF 1120, there is an infinite loop vulnerability and application hang in the pdf_parse_array function (pdf/pdf-parsec) because EOF is not considered Remote attackers could leverage this vulnerability to cause a denial of service via a crafted pdf file ...