Lucene search

K
redhatcveRedhat.comRH:CVE-2019-13290
HistoryMay 20, 2022 - 11:01 p.m.

CVE-2019-13290

2022-05-2023:01:40
redhat.com
access.redhat.com
10
artifex mupdf
heap-based
buffer overflow
fz_append_display_node
remote attackers
arbitrary code
crafted pdf
bdc property.

EPSS

0.011

Percentile

84.3%

Artifex MuPDF 1.15.0 has a heap-based buffer overflow in fz_append_display_node located at fitz/list-device.c, allowing remote attackers to execute arbitrary code via a crafted PDF file. This occurs with a large BDC property name that overflows the allocated size of a display list node.