CVE-2018-1000051: Use After Free
Published Feb 9, 2018
·Updated
Artifex Mupdf version 1.12.0 contains a Use After Free vulnerability in fzkeepkeystorable that can result in DOS / Possible code execution. This attack appear to be exploitable via Victim opens a specially crafted PDF.
Affected Software
4 affected componentsFixes available
debian/mupdf
1.14.0+ds1-4+deb10u31.14.0+ds1-4+deb10u21.17.0+ds1-21.17.0+ds1-1.3~deb11u11.21.1+ds2-11.22.2+ds1-2
Artifex Mupdf=1.12.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Remediation
Patch Available
Event History
Feb 9, 2018
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2018-1000051.
2
What is the severity level of CVE-2018-1000051?
The severity level of CVE-2018-1000051 is high with a severity value of 7.8.
3
What is the affected software for this vulnerability?
The affected software for this vulnerability is Artifex Mupdf version 1.12.0.
4
How can this vulnerability be exploited?
This vulnerability can be exploited by opening a specially crafted PDF.
5
How can I fix CVE-2018-1000051?
To fix CVE-2018-1000051, update to a version of Artifex Mupdf that is equal to or greater than 1.14.0+ds1-4+deb10u3, 1.14.0+ds1-4+deb10u2, 1.17.0+ds1-2, 1.17.0+ds1-1.3~deb11u1, 1.21.1+ds2-1, or 1.22.2+ds1-2.