Описание
In Artifex MuPDF 1.14.0, svg/svg-run.c allows remote attackers to cause a denial of service (recursive calls followed by a fitz/xml.c fz_xml_att crash from excessive stack consumption) via a crafted svg file, as demonstrated by mupdf-gl.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| mupdf | fixed | 1.15.0+ds1-1 | package | |
| mupdf | not-affected | buster | package | |
| mupdf | not-affected | stretch | package |
Примечания
Negligable security impact, crash in CLI tool
https://bugs.ghostscript.com/show_bug.cgi?id=700342
https://github.com/TeamSeri0us/pocs/tree/master/mupdf/20181203
Fixed by: https://git.ghostscript.com/?p=mupdf.git;a=commitdiff;h=a7f7d91cdff8d303c11d458fa8b802776f73c8cc
EPSS
Связанные уязвимости
In Artifex MuPDF 1.14.0, svg/svg-run.c allows remote attackers to cause a denial of service (recursive calls followed by a fitz/xml.c fz_xml_att crash from excessive stack consumption) via a crafted svg file, as demonstrated by mupdf-gl.
In Artifex MuPDF 1.14.0, svg/svg-run.c allows remote attackers to cause a denial of service (recursive calls followed by a fitz/xml.c fz_xml_att crash from excessive stack consumption) via a crafted svg file, as demonstrated by mupdf-gl.
In Artifex MuPDF 1.14.0, svg/svg-run.c allows remote attackers to cause a denial of service (recursive calls followed by a fitz/xml.c fz_xml_att crash from excessive stack consumption) via a crafted svg file, as demonstrated by mupdf-gl.
EPSS