CVE-2018-10289: Medium severity artifex software mupdf vulnerability
Published Apr 22, 2018
·Updated
In MuPDF 1.13.0, there is an infinite loop in the fzskipspace function of the pdf/pdf-xref.c file. A remote adversary could leverage this vulnerability to cause a denial of service via a crafted pdf file.
Affected Software
2 affected components
Artifex Mupdf=1.13.0
Debian Debian Linux=9.0
Event History
Apr 22, 2018
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is CVE-2018-10289?
CVE-2018-10289 is a vulnerability in MuPDF 1.13.0 that allows a remote attacker to cause a denial of service via a crafted PDF file.
2
What is the severity of CVE-2018-10289?
The severity of CVE-2018-10289 is medium with a CVSS score of 5.5.
3
How does CVE-2018-10289 affect Artifex Mupdf 1.13.0?
CVE-2018-10289 affects Artifex Mupdf 1.13.0 by causing an infinite loop in the fz_skip_space function of the pdf/pdf-xref.c file.
4
How does CVE-2018-10289 affect Debian Debian Linux 9.0?
CVE-2018-10289 affects Debian Debian Linux 9.0 by causing an infinite loop in the fz_skip_space function of the pdf/pdf-xref.c file.
5
How can CVE-2018-10289 be mitigated?
To mitigate CVE-2018-10289, it is recommended to update to a patched version of MuPDF.