First published: Tue Feb 23 2021(Updated: )
A flaw was found in mupdf 1.18.0. Double free of object during linearization may lead to memory corruption and other potential consequences.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Artifex Mupdf | =1.18.0 | |
Fedoraproject Fedora | =32 | |
Fedoraproject Fedora | =33 | |
Fedoraproject Fedora | =34 | |
Debian Debian Linux | =9.0 | |
=1.18.0 | ||
=32 | ||
=33 | ||
=34 | ||
=9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-3407 is a vulnerability found in mupdf 1.18.0 that allows for double free of object during linearization, which can lead to memory corruption and other potential consequences.
CVE-2021-3407 has a severity rating of medium with a value of 5.5.
CVE-2021-3407 affects mupdf 1.18.0, Fedoraproject Fedora versions 32, 33, and 34, and Debian Debian Linux version 9.0.
CVE-2021-3407 can be exploited through a double free of object during linearization in mupdf 1.18.0.
Yes, you can find references for CVE-2021-3407 at the following links: [http://git.ghostscript.com/?p=mupdf.git%3Bh=cee7cefc610d42fd383b3c80c12cbc675443176a](http://git.ghostscript.com/?p=mupdf.git%3Bh=cee7cefc610d42fd383b3c80c12cbc675443176a), [https://lists.debian.org/debian-lts-announce/2021/03/msg00012.html](https://lists.debian.org/debian-lts-announce/2021/03/msg00012.html), and [https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LCADE3VSPWCGTE5BV4KL273R5VK3GDKM/](https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LCADE3VSPWCGTE5BV4KL273R5VK3GDKM/).