First published: Wed Aug 14 2019(Updated: )
Artifex MuPDF before 1.16.0 has a heap-based buffer over-read in fz_chartorune in fitz/string.c because pdf/pdf-op-filter.c does not check for a missing string.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Artifex Mupdf | <1.16.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2019-14975.
The severity of CVE-2019-14975 is high with a score of 7.1.
The affected software in CVE-2019-14975 is Artifex MuPDF before version 1.16.0.
CVE-2019-14975 is a heap-based buffer over-read vulnerability in Artifex MuPDF before version 1.16.0.
To fix CVE-2019-14975, update Artifex MuPDF to version 1.16.0 or later.