#VU117353 Use-after-free in MuPDF - CVE-2020-21896
Published: October 17, 2025
MuPDF
Artifex Software, Inc.
Description
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error within the svg_dev_text_span_as_paths_defs() function in source/fitz/svg-device.c when handling PDF files. A remote attacker can pass specially crafted input to the application and compromise the affected system.
Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.