CVE-2018-6187: Buffer Overflow
In Artifex MuPDF 1.12.0, there is a heap-based buffer overflow vulnerability in the dopdfsavedocument function in the pdf/pdf-write.c file. Remote attackers could leverage the vulnerability to cause a denial of service via a crafted pdf file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/mupdfto a version that resolves this vulnerability.Fixed in 1.14.0+ds1-4+deb10u3Fixed in 1.14.0+ds1-4+deb10u2Fixed in 1.17.0+ds1-2Fixed in 1.17.0+ds1-1.3~deb11u1Fixed in 1.21.1+ds2-1Fixed in 1.22.2+ds1-2
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-6187.
What is the severity of CVE-2018-6187?
The severity of CVE-2018-6187 is medium with a severity value of 5.5.
How does the vulnerability impact Artifex MuPDF 1.12.0?
The vulnerability can be leveraged by remote attackers to cause a denial of service by exploiting a heap-based buffer overflow in the do_pdf_save_document function.
How can I fix the vulnerability in Artifex MuPDF?
To fix the vulnerability, update Artifex MuPDF to version 1.14.0+ds1-4+deb10u3 or later.
Are there any additional references related to CVE-2018-6187?
Yes, you can find additional references related to CVE-2018-6187 at the following links: [1] http://www.securityfocus.com/bid/102823, [2] https://bugs.ghostscript.com/show_bug.cgi?id=698908, [3] https://security.gentoo.org/glsa/201811-15