First published: Fri Jan 11 2019(Updated: )
Artifex MuPDF 1.14.0 has a SEGV in the function fz_load_page of the fitz/document.c file, as demonstrated by mutool. This is related to page-number mishandling in cbz/mucbz.c, cbz/muimg.c, and svg/svg-doc.c.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Artifex Mupdf | =1.14.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-6130.
The severity of CVE-2019-6130 is medium with a severity value of 5.5.
The affected software is Artifex MuPDF version 1.14.0.
The vulnerability can be exploited by performing a specially crafted operation on MuPDF, which may lead to a segmentation fault and denial of service.
Yes, you can find more information about this vulnerability in the following references: http://www.securityfocus.com/bid/106558, https://bugs.ghostscript.com/show_bug.cgi?id=700446, https://lists.debian.org/debian-lts-announce/2019/06/msg00027.html