First published: Thu Jun 13 2019(Updated: )
Usage of an uninitialized variable in the function fz_load_jpeg in Artifex MuPDF 1.14 can result in a heap overflow vulnerability that allows an attacker to execute arbitrary code.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Artifex Mupdf | =1.14.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-7321 is a vulnerability in Artifex MuPDF 1.14 that allows an attacker to execute arbitrary code through a heap overflow.
CVE-2019-7321 has a severity rating of 9.8, which is classified as critical.
CVE-2019-7321 affects Artifex MuPDF 1.14, specifically in the function fz_load_jpeg, where the usage of an uninitialized variable can result in a heap overflow vulnerability.
An attacker can exploit CVE-2019-7321 by executing arbitrary code through the heap overflow vulnerability in Artifex MuPDF 1.14.
Yes, a fix for CVE-2019-7321 is available and users should update to the patched version of Artifex MuPDF 1.14.