First published: Thu May 24 2018(Updated: )
In Artifex MuPDF 1.12.0 and earlier, multiple reachable assertions in the PDF parser allow an attacker to cause a denial of service (assert crash) via a crafted file.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/mupdf | 1.14.0+ds1-4+deb10u3 1.14.0+ds1-4+deb10u2 1.17.0+ds1-2 1.17.0+ds1-1.3~deb11u1 1.21.1+ds2-1 1.22.2+ds1-2 | |
Artifex Software MuPDF | <=1.12.0 | |
Debian GNU/Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1000037 is classified as a denial of service vulnerability due to multiple reachable assertions in the PDF parser.
To fix CVE-2018-1000037, update to MuPDF versions 1.14.0+ds1-4+deb10u2 or later.
MuPDF versions up to and including 1.12.0 are affected by CVE-2018-1000037.
CVE-2018-1000037 allows attackers to cause denial of service by using crafted PDF files.
Users of Artifex MuPDF 1.12.0 and earlier, especially those running Debian 9.0, are affected by CVE-2018-1000037.