First published: Thu Sep 22 2016(Updated: )
Use-after-free vulnerability in the pdf_load_xref function in pdf/pdf-xref.c in MuPDF allows remote attackers to cause a denial of service (crash) via a crafted PDF file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Artifex Software MuPDF | <=1.9 | |
SUSE Linux | =42.1 | |
SUSE Linux | =13.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-6265 is considered a denial of service vulnerability that could lead to application crashes.
To fix CVE-2016-6265, upgrade to a version of MuPDF that is newer than 1.9, if available.
CVE-2016-6265 affects MuPDF versions up to and including 1.9, as well as specific versions of openSUSE.
Yes, CVE-2016-6265 can be exploited by remote attackers using crafted PDF files.
CVE-2016-6265 is associated with use-after-free attacks that result in denial of service.