Buffer overflow in MuPDF - CVE-2017-17866
Published: November 5, 2018 / Updated: November 6, 2018
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The vulnerability exists due to boundary error in pdf/pdf-write.c when a repair operation occurs during a clean operation. A remote attacker can trick the victim into opening a specially crafted PDF document, trigger memory corruption and cause the service to crash.
Affected software
Debian Linux
Fedora
mupdf
How to mitigate CVE-2017-17866
mupdf - addressed in versions 1.12.0-1.fc26, 1.12.0-1.fc27