CVE-2018-6192: Buffer Overflow
In Artifex MuPDF 1.12.0, the pdfreadnewxref function in pdf/pdf-xref.c allows remote attackers to cause a denial of service (segmentation violation and application crash) via a crafted pdf file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/mupdfto a version that resolves this vulnerability.Fixed in 1.14.0+ds1-4+deb10u3Fixed in 1.14.0+ds1-4+deb10u2Fixed in 1.17.0+ds1-2Fixed in 1.17.0+ds1-1.3~deb11u1Fixed in 1.21.1+ds2-1Fixed in 1.22.2+ds1-2
Event History
Frequently Asked Questions
What is the vulnerability ID for this Artifex MuPDF vulnerability?
The vulnerability ID for this Artifex MuPDF vulnerability is CVE-2018-6192.
What is the severity level of CVE-2018-6192?
The severity level of CVE-2018-6192 is medium.
How does CVE-2018-6192 impact Artifex MuPDF?
CVE-2018-6192 allows remote attackers to cause a denial of service (segmentation violation and application crash) in Artifex MuPDF 1.12.0.
How can I fix CVE-2018-6192 in Artifex MuPDF?
To fix CVE-2018-6192 in Artifex MuPDF, you should update to version 1.14.0+ds1-4+deb10u3 or later.
Where can I find more information about CVE-2018-6192?
You can find more information about CVE-2018-6192 at the following references: [1] [2] [3].