CVE-2018-1000037: Input Validation
In Artifex MuPDF 1.12.0 and earlier, multiple reachable assertions in the PDF parser allow an attacker to cause a denial of service (assert crash) via a crafted file.
Other sources
In MuPDF 1.12.0 and earlier, multiple reachable assertions in the PDF parser allow an attacker to cause a denial of service (assert crash) via a crafted file.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1000037?
CVE-2018-1000037 is classified as a denial of service vulnerability due to multiple reachable assertions in the PDF parser.
How do I fix CVE-2018-1000037?
To fix CVE-2018-1000037, update to MuPDF versions 1.14.0+ds1-4+deb10u2 or later.
What versions of MuPDF are affected by CVE-2018-1000037?
MuPDF versions up to and including 1.12.0 are affected by CVE-2018-1000037.
What types of attacks are possible with CVE-2018-1000037?
CVE-2018-1000037 allows attackers to cause denial of service by using crafted PDF files.
Who is affected by CVE-2018-1000037?
Users of Artifex MuPDF 1.12.0 and earlier, especially those running Debian 9.0, are affected by CVE-2018-1000037.