CVE-2014-2013: Buffer Overflow
Published Mar 3, 2014
·Updated
Stack-based buffer overflow in the xpsparsecolor function in xps/xps-common.c in MuPDF 1.3 and earlier allows remote attackers to execute arbitrary code via a large number of entries in the ContextColor value of the Fill attribute in a Path element.
Affected Software
4 affected components
Artifex Mupdf<=1.3
Artifex Mupdf=1.0
Artifex Mupdf=1.1
Artifex Mupdf=1.2
Event History
Mar 3, 2014
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
via NVD·04:55 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-2013?
CVE-2014-2013 is considered to have a critical severity due to its potential for remote code execution.
2
How do I fix CVE-2014-2013?
To fix CVE-2014-2013, update MuPDF to version 1.4 or later where this vulnerability is patched.
3
What systems are affected by CVE-2014-2013?
CVE-2014-2013 affects MuPDF versions 1.3 and earlier.
4
What type of vulnerability is CVE-2014-2013?
CVE-2014-2013 is a stack-based buffer overflow vulnerability.
5
Can CVE-2014-2013 be exploited remotely?
Yes, CVE-2014-2013 can be exploited remotely through specially crafted XPS files.