Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-5686

Опубликовано: 14 янв. 2018
Источник: debian
EPSS Низкий

Описание

In MuPDF 1.12.0, there is an infinite loop vulnerability and application hang in the pdf_parse_array function (pdf/pdf-parse.c) because EOF is not considered. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted pdf file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mupdffixed1.13.0+ds1-1package
mupdfno-dsawheezypackage

Примечания

  • https://bugs.ghostscript.com/show_bug.cgi?id=698860

  • pdf_parse_array function in source/pdf/pdf-parse.c does not consider

  • EOF.

  • Fixed by: https://git.ghostscript.com/?p=mupdf.git;h=b70eb93f6936c03d8af52040bbca4d4a7db39079

EPSS

Процентиль: 59%
0.0038
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 8 лет назад

In MuPDF 1.12.0, there is an infinite loop vulnerability and application hang in the pdf_parse_array function (pdf/pdf-parse.c) because EOF is not considered. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted pdf file.

CVSS3: 5.5
nvd
около 8 лет назад

In MuPDF 1.12.0, there is an infinite loop vulnerability and application hang in the pdf_parse_array function (pdf/pdf-parse.c) because EOF is not considered. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted pdf file.

CVSS3: 5.5
github
больше 3 лет назад

In MuPDF 1.12.0, there is an infinite loop vulnerability and application hang in the pdf_parse_array function (pdf/pdf-parse.c) because EOF is not considered. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted pdf file.

suse-cvrf
около 8 лет назад

Security update for mupdf

EPSS

Процентиль: 59%
0.0038
Низкий