CVE-2017-5991: Null Pointer Dereference
An issue was discovered in Artifex MuPDF before 1912de5f08e90af1d9d0a9791f58ba3afdb9d465. The pdfrunxobject function in pdf-op-run.c encounters a NULL pointer dereference during a Fitz fzpaintpixmapwithmask painting operation. Versions 1.11 and later are unaffected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.11 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch 1912de5f08e90af1d9d0a9791f58ba3afdb9d465
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5991?
CVE-2017-5991 has been classified as having moderate severity due to the potential for a NULL pointer dereference leading to application instability.
How do I fix CVE-2017-5991?
To fix CVE-2017-5991, upgrade to MuPDF version 1.11 or later, which is not affected by this vulnerability.
Which software versions are affected by CVE-2017-5991?
CVE-2017-5991 affects MuPDF versions prior to 1.11 and Debian GNU/Linux versions 8.0 and 9.0.
What type of vulnerability is CVE-2017-5991?
CVE-2017-5991 is a NULL pointer dereference vulnerability occurring in the pdf_run_xobject function.
Can CVE-2017-5991 be exploited remotely?
Yes, CVE-2017-5991 can be exploited remotely during PDF file processing, leading to application crashes.