Stack overflow in MuPDF - CVE-2016-10221
Published: June 6, 2017 / Updated: June 10, 2017
Vulnerability identifier: #VU6920
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-10221
CWE-ID: CWE-121
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error within the count_entries() function in pdf-layer.c in MuPDF 1.10a. A remote attacker can create a specially crafted PDF file, trick the victim into opening it and crash, trigger stack overflow and crash the application.
The vulnerability exists due to a boundary error within the count_entries() function in pdf-layer.c in MuPDF 1.10a. A remote attacker can create a specially crafted PDF file, trick the victim into opening it and crash, trigger stack overflow and crash the application.
Affected software
MuPDF
Gentoo Linux
Fedora
mupdf
Gentoo Linux
Fedora
mupdf
How to mitigate CVE-2016-10221
Update to version 1.11-r1.
mupdf - addressed in versions 1.10a-5.fc25, 1.10a-5.fc26