First published: Mon May 15 2017(Updated: )
An exploitable heap out of bounds write vulnerability exists in the Fitz graphical library part of the MuPDF renderer. A specially crafted PDF file can cause a out of bounds write resulting in heap metadata and sensitive process memory corruption leading to potential code execution. Victim needs to open the specially crafted file in a vulnerable reader in order to trigger this vulnerability.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
Artifex Mupdf | =1.10-rc1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-8728 is an exploitable heap out of bounds write vulnerability in the Fitz graphical library part of the MuPDF renderer.
The severity of CVE-2016-8728 is high, with a CVSS score of 7.8.
The Artifex Mupdf version 1.10-rc1 is affected by CVE-2016-8728.
CVE-2016-8728 can be exploited by specially crafted PDF files, causing an out of bounds write leading to potential code execution.
Yes, it is recommended to update to a patched version of Artifex Mupdf to fix CVE-2016-8728.