CVE-2018-18662: Medium severity artifex software mupdf vulnerability
Published Oct 26, 2018
·Updated
There is an out-of-bounds read in fzrunt3glyph in fitz/font.c in Artifex MuPDF 1.14.0, as demonstrated by mutool.
Affected Software
1 affected component
Artifex Mupdf=1.14.0
Event History
Oct 26, 2018
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this out-of-bounds read in Artifex MuPDF?
The vulnerability ID for this out-of-bounds read in Artifex MuPDF is CVE-2018-18662.
2
What is the severity of CVE-2018-18662?
The severity of CVE-2018-18662 is medium with a severity value of 5.5.
3
What is affected by this vulnerability?
Artifex MuPDF version 1.14.0 is affected by this vulnerability.
4
How can I fix the out-of-bounds read vulnerability in Artifex MuPDF?
To fix the out-of-bounds read vulnerability in Artifex MuPDF, it is recommended to update to a version beyond 1.14.0.
5
Where can I find more information about this vulnerability?
More information about this vulnerability can be found at the following references: [1](http://www.securityfocus.com/bid/105755), [2](https://bugs.ghostscript.com/show_bug.cgi?id=700043), [3](https://github.com/TeamSeri0us/pocs/tree/master/mupdf).