CVE-2018-1000039: Use After Free
In Artifex MuPDF 1.12.0 and earlier, multiple heap use after free bugs in the PDF parser could allow an attacker to execute arbitrary code, read memory, or cause a denial of service via a crafted file.
Other sources
In MuPDF 1.12.0 and earlier, multiple heap use after free bugs in the PDF parser could allow an attacker to execute arbitrary code, read memory, or cause a denial of service via a crafted file.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this MuPDF vulnerability?
The vulnerability ID for this MuPDF vulnerability is CVE-2018-1000039.
What is the severity of CVE-2018-1000039?
CVE-2018-1000039 has a severity rating of 7.8, which is considered high.
What software versions are affected by CVE-2018-1000039?
MuPDF versions up to and including 1.12.0 are affected by CVE-2018-1000039.
How can an attacker exploit CVE-2018-1000039?
An attacker can exploit CVE-2018-1000039 by crafting a malicious file that triggers multiple heap use after free bugs in the PDF parser, allowing them to execute arbitrary code, read memory, or cause a denial of service.
Where can I find more information about CVE-2018-1000039?
You can find more information about CVE-2018-1000039 at the following references: [Reference 1](http://git.ghostscript.com/?p=mupdf.git;a=commitdiff;h=4dcc6affe04368461310a21238f7e1871a752a05;hp=8ec561d1bccc46e9db40a9f61310cd8b3763914e), [Reference 2](http://git.ghostscript.com/?p=mupdf.git;a=commitdiff;h=71ceebcf56e682504da22c4035b39a2d451e8ffd;hp=7f82c01523505052615492f8e220f4348ba46995), [Reference 3](http://git.ghostscript.com/?p=mupdf.git;a=commitdiff;h=f597300439e62f5e921f0d7b1e880b5c1a1f1607;hp=093fc3b098dc5fadef5d8ad4b225db9fb124758b).