CVE-2019-13290: Buffer Overflow
Artifex MuPDF 1.15.0 has a heap-based buffer overflow in fzappenddisplaynode located at fitz/list-device.c, allowing remote attackers to execute arbitrary code via a crafted PDF file. This occurs with a large BDC property name that overflows the allocated size of a display list node.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-13290?
CVE-2019-13290 is a vulnerability in Artifex MuPDF 1.15.0 that allows remote attackers to execute arbitrary code via a crafted PDF file.
How does CVE-2019-13290 occur?
CVE-2019-13290 occurs due to a heap-based buffer overflow in fz_append_display_node located at fitz/list-device.c.
What is the severity of CVE-2019-13290?
The severity of CVE-2019-13290 is high with a severity score of 7.8.
Which software versions are affected by CVE-2019-13290?
Artifex MuPDF 1.15.0 is affected by CVE-2019-13290.
How can I protect myself from CVE-2019-13290?
To protect yourself from CVE-2019-13290, update to a version of Artifex MuPDF that includes the fix.