First published: Wed Jul 21 2021(Updated: )
MuPDF through 1.18.1 has an out-of-bounds write because the cached color converter does not properly consider the maximum key size of a hash table. This can, for example, be seen with crafted "mutool draw" input.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Artifex Mupdf | <=1.18.1 | |
Fedoraproject Fedora | =34 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2021-37220.
The severity of CVE-2021-37220 is medium with a severity value of 5.5.
The affected software for CVE-2021-37220 is MuPDF 1.18.1 and Fedora 34.
CVE-2021-37220 is a vulnerability in MuPDF through 1.18.1 that allows for an out-of-bounds write due to improper consideration of the maximum key size of a hash table.
To fix CVE-2021-37220, it is recommended to update MuPDF to a version beyond 1.18.1 and apply any necessary patches.