CVE-2018-19882: Null Pointer Dereference
In Artifex MuPDF 1.14.0, the svgrunimage function in svg/svg-run.c allows remote attackers to cause a denial of service (hrefatt NULL pointer dereference and application crash) via a crafted svg file, as demonstrated by mupdf-gl.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-19882?
CVE-2018-19882 is a vulnerability in Artifex MuPDF 1.14.0 that allows remote attackers to cause a denial of service.
How does CVE-2018-19882 affect Artifex MuPDF?
CVE-2018-19882 affects Artifex MuPDF 1.14.0, allowing remote attackers to cause a denial of service.
What is the severity of CVE-2018-19882?
CVE-2018-19882 has a severity rating of 5.5 (medium).
How can I fix the CVE-2018-19882 vulnerability?
To fix the CVE-2018-19882 vulnerability, it is recommended to update Artifex MuPDF to a version that is not affected by the issue.
Where can I find more information about CVE-2018-19882?
Additional information about CVE-2018-19882 can be found at the following references: [link](https://bugs.ghostscript.com/show_bug.cgi?id=700342), [link](https://github.com/TeamSeri0us/pocs/tree/master/mupdf/20181203), [link](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CNJNEX5EW6YH5OARXXSSXW4HHC5PIBSY/)