CVE-2016-6265: Use After Free
Published Sep 22, 2016
·Updated
Use-after-free vulnerability in the pdfloadxref function in pdf/pdf-xref.c in MuPDF allows remote attackers to cause a denial of service (crash) via a crafted PDF file.
Affected Software
3 affected components
Artifex Mupdf<=1.9
openSUSE Leap=42.1
openSUSE openSUSE=13.2
Remediation
Patch Available
Event History
Sep 22, 2016
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-6265?
CVE-2016-6265 is considered a denial of service vulnerability that could lead to application crashes.
2
How do I fix CVE-2016-6265?
To fix CVE-2016-6265, upgrade to a version of MuPDF that is newer than 1.9, if available.
3
Which software is affected by CVE-2016-6265?
CVE-2016-6265 affects MuPDF versions up to and including 1.9, as well as specific versions of openSUSE.
4
Can CVE-2016-6265 be exploited remotely?
Yes, CVE-2016-6265 can be exploited by remote attackers using crafted PDF files.
5
What type of attack is associated with CVE-2016-6265?
CVE-2016-6265 is associated with use-after-free attacks that result in denial of service.