CVE-2019-6130: Medium severity artifex software mupdf vulnerability
Artifex MuPDF 1.14.0 has a SEGV in the function fzloadpage of the fitz/document.c file, as demonstrated by mutool. This is related to page-number mishandling in cbz/mucbz.c, cbz/muimg.c, and svg/svg-doc.c.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2019-6130.
What is the severity of CVE-2019-6130?
The severity of CVE-2019-6130 is medium with a severity value of 5.5.
What is the affected software?
The affected software is Artifex MuPDF version 1.14.0.
How can the vulnerability be exploited?
The vulnerability can be exploited by performing a specially crafted operation on MuPDF, which may lead to a segmentation fault and denial of service.
Are there any references related to this vulnerability?
Yes, you can find more information about this vulnerability in the following references: http://www.securityfocus.com/bid/106558, https://bugs.ghostscript.com/show_bug.cgi?id=700446, https://lists.debian.org/debian-lts-announce/2019/06/msg00027.html