First published: Thu Dec 06 2018(Updated: )
In Artifex MuPDF 1.14.0, svg/svg-run.c allows remote attackers to cause a denial of service (recursive calls followed by a fitz/xml.c fz_xml_att crash from excessive stack consumption) via a crafted svg file, as demonstrated by mupdf-gl.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Artifex Software MuPDF | =1.14.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-19881 is medium with a severity value of 5.5.
CVE-2018-19881 affects Artifex MuPDF version 1.14.0.
Remote attackers can cause a denial of service through recursive calls and excessive stack consumption by exploiting CVE-2018-19881.
The Common Weakness Enumeration (CWE) for CVE-2018-19881 is CWE-400, which is related to Uncontrolled Resource Consumption ('Resource Exhaustion').
Yes, upgrading to a version of Artifex MuPDF that is not affected by the vulnerability is the recommended fix for CVE-2018-19881.