Resource exhaustion in MuPDF - CVE-2018-19881
Published: December 6, 2018 / Updated: August 8, 2020
MuPDF
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
In Artifex MuPDF 1.14.0, svg/svg-run.c allows remote attackers to cause a denial of service (recursive calls followed by a fitz/xml.c fz_xml_att crash from excessive stack consumption) via a crafted svg file, as demonstrated by mupdf-gl.
How to mitigate CVE-2018-19881
Sources
- https://bugs.ghostscript.com/show_bug.cgi?id=700342
- https://github.com/TeamSeri0us/pocs/tree/master/mupdf/20181203
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CNJNEX5EW6YH5OARXXSSXW4HHC5PIBSY/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SEK2EHVNREJ7XZMFF2MXRWKIF4IBHPNE/