CVE-2017-17866: Buffer Overflow
pdf/pdf-write.c in Artifex MuPDF before 1.12.0 mishandles certain length changes when a repair operation occurs during a clean operation, which allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted PDF document.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2017-17866?
CVE-2017-17866 is a vulnerability in Artifex MuPDF before 1.12.0 that mishandles certain length changes, allowing remote attackers to cause a denial of service or potentially have other unspecified impacts via a crafted PDF document.
How severe is CVE-2017-17866?
CVE-2017-17866 has a severity rating of 7.8, which is considered high.
How does CVE-2017-17866 affect Artifex MuPDF?
CVE-2017-17866 affects Artifex MuPDF versions before 1.12.0.
How can CVE-2017-17866 be fixed?
To fix CVE-2017-17866, upgrade to Artifex MuPDF version 1.12.0 or later.
Where can I find more information about CVE-2017-17866?
More information about CVE-2017-17866 can be found in the references section of the vulnerability report.