CVE-2021-37220: Medium severity Artifex Mupdf vulnerability
Published Jul 21, 2021
·Updated
MuPDF through 1.18.1 has an out-of-bounds write because the cached color converter does not properly consider the maximum key size of a hash table. This can, for example, be seen with crafted "mutool draw" input.
Affected Software
2 affected components
Artifex Mupdf<=1.18.1
Fedoraproject Fedora=34
Remediation
Event History
Jul 21, 2021
CVE Published
via MITRE·09:02 PM
Data Sourced
via MITRE·09:02 PM
Description
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-37220.
2
What is the severity of CVE-2021-37220?
The severity of CVE-2021-37220 is medium with a severity value of 5.5.
3
What is the affected software for CVE-2021-37220?
The affected software for CVE-2021-37220 is MuPDF 1.18.1 and Fedora 34.
4
What is the description of CVE-2021-37220?
CVE-2021-37220 is a vulnerability in MuPDF through 1.18.1 that allows for an out-of-bounds write due to improper consideration of the maximum key size of a hash table.
5
How can I fix CVE-2021-37220?
To fix CVE-2021-37220, it is recommended to update MuPDF to a version beyond 1.18.1 and apply any necessary patches.