Out-of-bounds read in MuPDF - CVE-2018-18662
Published: October 26, 2018 / Updated: October 30, 2018
MuPDF
Detailed vulnerability description
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists due to out-of-bounds read in fz_run_t3_glyph in fitz/font.c when handling malicious input. A remote attacker can send specially crafted .pdf file, trigger out-of-bounds read and cause the application to crash.