First published: Wed May 24 2017(Updated: )
libjbig2dec.a in Artifex jbig2dec 0.13, as used in MuPDF and Ghostscript, has a NULL pointer dereference in the jbig2_huffman_get function in jbig2_huffman.c. For example, the jbig2dec utility will crash (segmentation fault) when parsing an invalid file.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Artifex GPL Ghostscript | =0.13 | |
MuPDF | =0.13 | |
Debian | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-9216 has a medium severity level due to potential denial of service caused by a NULL pointer dereference.
To fix CVE-2017-9216, update to the patched versions of libjbig2dec, specifically version 0.13 or later.
CVE-2017-9216 affects Artifex jbig2dec 0.13, which is used in applications like MuPDF and Ghostscript.
Yes, CVE-2017-9216 can cause crashes (segmentation faults) when the jbig2dec utility attempts to parse an invalid file.
CVE-2017-9216 is considered potentially exploitable if an attacker can provide an invalid JBIG2 file to the jbig2dec utility.