CVE-2018-19881: Medium severity artifex software mupdf vulnerability
In Artifex MuPDF 1.14.0, svg/svg-run.c allows remote attackers to cause a denial of service (recursive calls followed by a fitz/xml.c fzxmlatt crash from excessive stack consumption) via a crafted svg file, as demonstrated by mupdf-gl.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-19881?
The severity of CVE-2018-19881 is medium with a severity value of 5.5.
How does CVE-2018-19881 affect Artifex MuPDF?
CVE-2018-19881 affects Artifex MuPDF version 1.14.0.
How can remote attackers exploit CVE-2018-19881?
Remote attackers can cause a denial of service through recursive calls and excessive stack consumption by exploiting CVE-2018-19881.
What is the Common Weakness Enumeration (CWE) for CVE-2018-19881?
The Common Weakness Enumeration (CWE) for CVE-2018-19881 is CWE-400, which is related to Uncontrolled Resource Consumption ('Resource Exhaustion').
Is there a fix for CVE-2018-19881?
Yes, upgrading to a version of Artifex MuPDF that is not affected by the vulnerability is the recommended fix for CVE-2018-19881.