First published: Thu Sep 06 2018(Updated: )
In Artifex MuPDF 1.13.0, the fz_append_byte function in fitz/buffer.c allows remote attackers to cause a denial of service (segmentation fault) via a crafted pdf file. This is caused by a pdf/pdf-device.c pdf_dev_alpha array-index underflow.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Artifex Mupdf | =1.13.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-16648 is a vulnerability in Artifex MuPDF 1.13.0 that allows remote attackers to cause a denial of service (segmentation fault) via a crafted PDF file.
CVE-2018-16648 affects Artifex MuPDF 1.13.0.
The severity of CVE-2018-16648 is medium with a CVSS score of 5.5.
To fix CVE-2018-16648 in Artifex MuPDF, it is recommended to update to a version higher than 1.13.0.
More information about CVE-2018-16648 can be found at the following references: [1], [2].