First published: Thu Sep 06 2018(Updated: )
In Artifex MuPDF 1.13.0, the pdf_get_xref_entry function in pdf/pdf-xref.c allows remote attackers to cause a denial of service (segmentation fault in fz_write_data in fitz/output.c) via a crafted pdf file.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Artifex Mupdf | =1.13.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-16647 is a vulnerability in Artifex MuPDF 1.13.0 that allows remote attackers to cause a denial of service via a crafted pdf file.
CVE-2018-16647 has a severity rating of medium (5.5).
CVE-2018-16647 can be exploited by sending a crafted pdf file to the vulnerable Artifex MuPDF 1.13.0 software.
CVE-2018-16647 affects Artifex MuPDF 1.13.0.
Yes, Artifex released a fix for CVE-2018-16647. It is recommended to update to a patched version of Artifex MuPDF.