CVE-2018-16648: Out-of-bounds Read
Published Sep 6, 2018
·Updated
In Artifex MuPDF 1.13.0, the fzappendbyte function in fitz/buffer.c allows remote attackers to cause a denial of service (segmentation fault) via a crafted pdf file. This is caused by a pdf/pdf-device.c pdfdevalpha array-index underflow.
Affected Software
1 affected component
Artifex Mupdf=1.13.0
Event History
Sep 6, 2018
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-16648?
CVE-2018-16648 is a vulnerability in Artifex MuPDF 1.13.0 that allows remote attackers to cause a denial of service (segmentation fault) via a crafted PDF file.
2
How does CVE-2018-16648 affect Artifex MuPDF?
CVE-2018-16648 affects Artifex MuPDF 1.13.0.
3
What is the severity of CVE-2018-16648?
The severity of CVE-2018-16648 is medium with a CVSS score of 5.5.
4
How can I fix CVE-2018-16648 in Artifex MuPDF?
To fix CVE-2018-16648 in Artifex MuPDF, it is recommended to update to a version higher than 1.13.0.
5
Where can I find more information about CVE-2018-16648?
More information about CVE-2018-16648 can be found at the following references: [1], [2].