AI Score
Confidence
High
EPSS
Percentile
69.9%
In Artifex MuPDF 1.13.0, the fz_append_byte function in fitz/buffer.c allows remote attackers to cause a denial of service (segmentation fault) via a crafted pdf file. This is caused by a pdf/pdf-device.c pdf_dev_alpha array-index underflow.
bugs.ghostscript.com/show_bug.cgi?id=699685
cgit.ghostscript.com/cgi-bin/cgit.cgi/mupdf.git/commit/?id=38f883fe129a5e89306252a4676eaaf4bc968824
lists.debian.org/debian-lts-announce/2020/07/msg00019.html