CVE-2017-15369: Use After Free
Published Oct 16, 2017
·Updated
The buildfilterchain function in pdf/pdf-stream.c in Artifex MuPDF before 2017-09-25 mishandles a certain case where a variable may reside in a register, which allows remote attackers to cause a denial of service (Fitz fzdropimp use-after-free and application crash) or possibly have unspecified other impact via a crafted PDF document.
Affected Software
1 affected component
Artifex Mupdf<=1.11
Event History
Oct 16, 2017
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-15369?
CVE-2017-15369 has a medium severity rating due to its potential for causing denial of service.
2
How do I fix CVE-2017-15369?
To fix CVE-2017-15369, upgrade to MuPDF version 1.12 or later.
3
What issues does CVE-2017-15369 cause?
CVE-2017-15369 can lead to application crashes and denial of service conditions.
4
Which versions of MuPDF are affected by CVE-2017-15369?
MuPDF versions up to and including 1.11 are affected by CVE-2017-15369.
5
Is CVE-2017-15369 being actively exploited?
There is no publicly available information confirming active exploitation of CVE-2017-15369.