Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-19881

Опубликовано: 06 дек. 2018
Источник: debian
EPSS Низкий

Описание

In Artifex MuPDF 1.14.0, svg/svg-run.c allows remote attackers to cause a denial of service (recursive calls followed by a fitz/xml.c fz_xml_att crash from excessive stack consumption) via a crafted svg file, as demonstrated by mupdf-gl.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mupdffixed1.15.0+ds1-1package
mupdfnot-affectedbusterpackage
mupdfnot-affectedstretchpackage

Примечания

  • Negligable security impact, crash in CLI tool

  • https://bugs.ghostscript.com/show_bug.cgi?id=700342

  • https://github.com/TeamSeri0us/pocs/tree/master/mupdf/20181203

  • Fixed by: https://git.ghostscript.com/?p=mupdf.git;a=commitdiff;h=a7f7d91cdff8d303c11d458fa8b802776f73c8cc

EPSS

Процентиль: 62%
0.0043
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 7 лет назад

In Artifex MuPDF 1.14.0, svg/svg-run.c allows remote attackers to cause a denial of service (recursive calls followed by a fitz/xml.c fz_xml_att crash from excessive stack consumption) via a crafted svg file, as demonstrated by mupdf-gl.

CVSS3: 5.5
nvd
около 7 лет назад

In Artifex MuPDF 1.14.0, svg/svg-run.c allows remote attackers to cause a denial of service (recursive calls followed by a fitz/xml.c fz_xml_att crash from excessive stack consumption) via a crafted svg file, as demonstrated by mupdf-gl.

CVSS3: 5.5
github
больше 3 лет назад

In Artifex MuPDF 1.14.0, svg/svg-run.c allows remote attackers to cause a denial of service (recursive calls followed by a fitz/xml.c fz_xml_att crash from excessive stack consumption) via a crafted svg file, as demonstrated by mupdf-gl.

EPSS

Процентиль: 62%
0.0043
Низкий