CVE-2018-6544: Medium severity Artifex Mupdf vulnerability
pdfloadobjstm in pdf/pdf-xref.c in Artifex MuPDF 1.12.0 could reference the object stream recursively and therefore run out of error stack, which allows remote attackers to cause a denial of service via a crafted PDF document.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/mupdfto a version that resolves this vulnerability.Fixed in 1.14.0+ds1-4+deb10u3Fixed in 1.14.0+ds1-4+deb10u2Fixed in 1.17.0+ds1-2Fixed in 1.17.0+ds1-1.3~deb11u1Fixed in 1.21.1+ds2-1Fixed in 1.22.2+ds1-2
Event History
Frequently Asked Questions
What is CVE-2018-6544?
CVE-2018-6544 is a vulnerability in Artifex MuPDF 1.12.0 that could allow remote attackers to cause a denial of service via a crafted PDF document.
How severe is CVE-2018-6544?
CVE-2018-6544 has a severity rating of 5.5 (medium).
What software is affected by CVE-2018-6544?
The following software versions are affected: mupdf 1.12.0, debian_linux 8.0, debian_linux 9.0.
How can I fix CVE-2018-6544?
To fix CVE-2018-6544, update to the following versions: mupdf 1.14.0+ds1-4+deb10u3 or later, mupdf 1.17.0+ds1-2 or later, mupdf 1.21.1+ds2-1 or later, or mupdf 1.22.2+ds1-2 or later.
Where can I find more information about CVE-2018-6544?
You can find more information about CVE-2018-6544 at the following references: http://git.ghostscript.com/?p=mupdf.git;h=26527eef77b3e51c2258c8e40845bfbc015e405d, http://git.ghostscript.com/?p=mupdf.git;h=b03def134988da8c800adac1a38a41a1f09a1d89, https://bugs.ghostscript.com/show_bug.cgi?id=698830.