Lucene search

K
archlinuxArch LinuxASA-201608-22
HistoryAug 30, 2016 - 12:00 a.m.

mupdf: arbitrary code execution

2016-08-3000:00:00
Arch Linux
lists.archlinux.org
21

EPSS

0.061

Percentile

93.6%

Yu Hong and Zheng Jihong discovered a heap overflow vulnerability within
the pdf_load_mesh_params function, allowing an attacker to cause an
application crash (denial-of-service), or potentially to execute
arbitrary code with the privileges of the user running MuPDF, if a
specially crafted PDF file is processed.

OSVersionArchitecturePackageVersionFilename
anyanyanymupdf< 1.9a-5UNKNOWN