Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-14975

Опубликовано: 14 авг. 2019
Источник: debian
EPSS Низкий

Описание

Artifex MuPDF before 1.16.0 has a heap-based buffer over-read in fz_chartorune in fitz/string.c because pdf/pdf-op-filter.c does not check for a missing string.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mupdfnot-affectedpackage

Примечания

  • https://bugs.ghostscript.com/show_bug.cgi?id=701292

  • Introduced by: https://git.ghostscript.com/?p=mupdf.git;a=commit;h=abcb3e68670ebc2e5127953462a026fe1a5dd321 (1.16.0-rc1)

  • Fixed by: https://git.ghostscript.com/?p=mupdf.git;a=commit;h=97096297d409ec6f206298444ba00719607e8ba8 (1.16.0)

EPSS

Процентиль: 44%
0.0022
Низкий

Связанные уязвимости

CVSS3: 7.1
ubuntu
больше 6 лет назад

Artifex MuPDF before 1.16.0 has a heap-based buffer over-read in fz_chartorune in fitz/string.c because pdf/pdf-op-filter.c does not check for a missing string.

CVSS3: 7.1
nvd
больше 6 лет назад

Artifex MuPDF before 1.16.0 has a heap-based buffer over-read in fz_chartorune in fitz/string.c because pdf/pdf-op-filter.c does not check for a missing string.

CVSS3: 7.1
github
больше 3 лет назад

Artifex MuPDF before 1.16.0 has a heap-based buffer over-read in fz_chartorune in fitz/string.c because pdf/pdf-op-filter.c does not check for a missing string.

EPSS

Процентиль: 44%
0.0022
Низкий