First published: Fri Sep 22 2017(Updated: )
Artifex MuPDF 1.11 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .xps file, related to "Data from Faulting Address controls Branch Selection starting at mupdf+0x000000000016aa61" on Windows. This occurs because xps_load_links_in_glyphs in xps/xps-link.c does not verify that an xps font could be loaded.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Artifex Software MuPDF | =1.11 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-14685 is considered a denial of service vulnerability that can potentially impact system availability.
To fix CVE-2017-14685, upgrade to a patched version of MuPDF that addresses this vulnerability.
CVE-2017-14685 can enable attackers to cause denial of service attacks through crafted .xps files.
CVE-2017-14685 impacts the MuPDF application on Windows systems.
CVE-2017-14685 specifically affects Artifex MuPDF version 1.11.