First published: Wed Feb 15 2017(Updated: )
An issue was discovered in Artifex MuPDF before 1912de5f08e90af1d9d0a9791f58ba3afdb9d465. The pdf_run_xobject function in pdf-op-run.c encounters a NULL pointer dereference during a Fitz fz_paint_pixmap_with_mask painting operation. Versions 1.11 and later are unaffected.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Artifex Software MuPDF | <1.11 | |
Debian GNU/Linux | =8.0 | |
Debian GNU/Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-5991 has been classified as having moderate severity due to the potential for a NULL pointer dereference leading to application instability.
To fix CVE-2017-5991, upgrade to MuPDF version 1.11 or later, which is not affected by this vulnerability.
CVE-2017-5991 affects MuPDF versions prior to 1.11 and Debian GNU/Linux versions 8.0 and 9.0.
CVE-2017-5991 is a NULL pointer dereference vulnerability occurring in the pdf_run_xobject function.
Yes, CVE-2017-5991 can be exploited remotely during PDF file processing, leading to application crashes.