6.8
CVSSv2

CVE-2019-13290

Published: 04/07/2019 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Artifex MuPDF 1.15.0 has a heap-based buffer overflow in fz_append_display_node located at fitz/list-device.c, allowing remote malicious users to execute arbitrary code via a crafted PDF file. This occurs with a large BDC property name that overflows the allocated size of a display list node.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

artifex mupdf 1.15.0

Vendor Advisories

Debian Bug report logs - #931475 mupdf: CVE-2019-13290 Package: src:mupdf; Maintainer for src:mupdf is Kan-Ru Chen (陳侃如) <koster@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 5 Jul 2019 19:21:08 UTC Severity: important Tags: security, upstream Found in version mupdf/1140+ds1- ...
A heap-based buffer overflow flaw was discovered in MuPDF, a lightweight PDF viewer, which may result in denial of service or the execution of arbitrary code if a malformed PDF file is opened For the stable distribution (buster), this problem has been fixed in version 1140+ds1-4+deb10u1 We recommend that you upgrade your mupdf packages For the ...