First published: Thu Dec 06 2018(Updated: )
In Artifex MuPDF 1.14.0, the svg_run_image function in svg/svg-run.c allows remote attackers to cause a denial of service (href_att NULL pointer dereference and application crash) via a crafted svg file, as demonstrated by mupdf-gl.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Artifex Mupdf | =1.14.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19882 is a vulnerability in Artifex MuPDF 1.14.0 that allows remote attackers to cause a denial of service.
CVE-2018-19882 affects Artifex MuPDF 1.14.0, allowing remote attackers to cause a denial of service.
CVE-2018-19882 has a severity rating of 5.5 (medium).
To fix the CVE-2018-19882 vulnerability, it is recommended to update Artifex MuPDF to a version that is not affected by the issue.
Additional information about CVE-2018-19882 can be found at the following references: [link](https://bugs.ghostscript.com/show_bug.cgi?id=700342), [link](https://github.com/TeamSeri0us/pocs/tree/master/mupdf/20181203), [link](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CNJNEX5EW6YH5OARXXSSXW4HHC5PIBSY/)