CVE-2023-51104: Divide by Zero
Published Dec 26, 2023
·Updated
A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in function pnmbinaryreadimage() of load-pnm.c when span equals zero.
Affected Software
1 affected component
Artifex Mupdf=1.23.4
Event History
Dec 26, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-51104?
The severity of CVE-2023-51104 is rated as high due to the potential for a crash or denial of service from a floating point exception.
2
How do I fix CVE-2023-51104?
To fix CVE-2023-51104, update Artifex MuPDF to the latest version that addresses this vulnerability.
3
What software versions are affected by CVE-2023-51104?
CVE-2023-51104 specifically affects Artifex MuPDF version 1.23.4.
4
What causes the vulnerability in CVE-2023-51104?
CVE-2023-51104 is caused by a divide-by-zero error in the function pnm_binary_read_image() when span equals zero.
5
Can CVE-2023-51104 be exploited remotely?
Yes, CVE-2023-51104 can potentially be exploited remotely if an attacker can manipulate input to trigger the floating point exception.