CVE-2017-14685: Buffer Overflow
Artifex MuPDF 1.11 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .xps file, related to "Data from Faulting Address controls Branch Selection starting at mupdf+0x000000000016aa61" on Windows. This occurs because xpsloadlinksinglyphs in xps/xps-link.c does not verify that an xps font could be loaded.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14685?
CVE-2017-14685 is considered a denial of service vulnerability that can potentially impact system availability.
How do I fix CVE-2017-14685?
To fix CVE-2017-14685, upgrade to a patched version of MuPDF that addresses this vulnerability.
What types of attacks can CVE-2017-14685 enable?
CVE-2017-14685 can enable attackers to cause denial of service attacks through crafted .xps files.
Is CVE-2017-14685 specific to any operating systems?
CVE-2017-14685 impacts the MuPDF application on Windows systems.
What is the product affected by CVE-2017-14685?
CVE-2017-14685 specifically affects Artifex MuPDF version 1.11.