First published: Fri Oct 26 2018(Updated: )
There is an out-of-bounds read in fz_run_t3_glyph in fitz/font.c in Artifex MuPDF 1.14.0, as demonstrated by mutool.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Artifex Mupdf | =1.14.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this out-of-bounds read in Artifex MuPDF is CVE-2018-18662.
The severity of CVE-2018-18662 is medium with a severity value of 5.5.
Artifex MuPDF version 1.14.0 is affected by this vulnerability.
To fix the out-of-bounds read vulnerability in Artifex MuPDF, it is recommended to update to a version beyond 1.14.0.
More information about this vulnerability can be found at the following references: [1](http://www.securityfocus.com/bid/105755), [2](https://bugs.ghostscript.com/show_bug.cgi?id=700043), [3](https://github.com/TeamSeri0us/pocs/tree/master/mupdf).