CVE-2016-8728: High severity Artifex Mupdf vulnerability
An exploitable heap out of bounds write vulnerability exists in the Fitz graphical library part of the MuPDF renderer. A specially crafted PDF file can cause a out of bounds write resulting in heap metadata and sensitive process memory corruption leading to potential code execution. Victim needs to open the specially crafted file in a vulnerable reader in order to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2016-8728?
CVE-2016-8728 is an exploitable heap out of bounds write vulnerability in the Fitz graphical library part of the MuPDF renderer.
What is the severity of CVE-2016-8728?
The severity of CVE-2016-8728 is high, with a CVSS score of 7.8.
What software is affected by CVE-2016-8728?
The Artifex Mupdf version 1.10-rc1 is affected by CVE-2016-8728.
How can CVE-2016-8728 be exploited?
CVE-2016-8728 can be exploited by specially crafted PDF files, causing an out of bounds write leading to potential code execution.
Is there any fix available for CVE-2016-8728?
Yes, it is recommended to update to a patched version of Artifex Mupdf to fix CVE-2016-8728.