First published: Tue Aug 22 2023(Updated: )
A Use After Free vulnerability in svg_dev_text_span_as_paths_defs function in source/fitz/svg-device.c in Artifex Software MuPDF 1.16.0 allows remote attackers to cause a denial of service via opening of a crafted PDF file.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Artifex Mupdf | =1.16.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-21896 is a Use After Free vulnerability in the svg_dev_text_span_as_paths_defs function in Artifex Software MuPDF 1.16.0.
CVE-2020-21896 affects Artifex Software MuPDF 1.16.0 by allowing remote attackers to cause a denial of service through a crafted PDF file.
CVE-2020-21896 has a severity rating of medium (5.5).
To fix CVE-2020-21896, it is recommended to update to a version of Artifex Software MuPDF that is not affected by the vulnerability.
For more information about CVE-2020-21896, you can refer to the official bug report at: https://bugs.ghostscript.com/show_bug.cgi?id=701294