Heap-based buffer overflow in MuPDF - CVE-2018-6187
Published: May 10, 2018
Vulnerability identifier: #VU12558
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-6187
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the traget system.
The weakness exists in the do_pdf_save_document function in the pdf/pdf-write.c file due to heap-based buffer overflow. A remote attacker can trick the victim into opening a specially crafted pdf file, trigger memory corruption and cause the service to crash.
The weakness exists in the do_pdf_save_document function in the pdf/pdf-write.c file due to heap-based buffer overflow. A remote attacker can trick the victim into opening a specially crafted pdf file, trigger memory corruption and cause the service to crash.
Affected software
MuPDF
Arch Linux
Debian Linux
Fedora
mupdf (Alpine package)
mupdf
Arch Linux
Debian Linux
Fedora
mupdf (Alpine package)
mupdf
How to mitigate CVE-2018-6187
Install update from vendor's website.
mupdf (Alpine package) - update to 1.13.0-r0
mupdf - update to 1.12.0-5.fc27
mupdf - update to 1.12.0-5.fc27