Memory corruption in MuPDF - CVE-2018-6192
Published: May 10, 2018
Vulnerability identifier: #VU12560
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-6192
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the traget system.
The weakness exists the pdf_read_new_xref function in pdf/pdf-xref.c due to segmentation violation. A remote attacker can trick the victim into opening a specially crafted pdf file, trigger memory corruption and cause the service to crash.
The weakness exists the pdf_read_new_xref function in pdf/pdf-xref.c due to segmentation violation. A remote attacker can trick the victim into opening a specially crafted pdf file, trigger memory corruption and cause the service to crash.
Affected software
MuPDF
Arch Linux
Debian Linux
Fedora
mupdf (Alpine package)
mupdf
Arch Linux
Debian Linux
Fedora
mupdf (Alpine package)
mupdf
How to mitigate CVE-2018-6192
Install update from vendor's website.
mupdf (Alpine package) - update to 1.13.0-r0
mupdf - update to 1.12.0-5.fc27
mupdf - update to 1.12.0-5.fc27