Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-16600

Опубликовано: 09 дек. 2020
Источник: debian

Описание

A Use After Free vulnerability exists in Artifex Software, Inc. MuPDF library 1.17.0-rc1 and earlier when a valid page was followed by a page with invalid pixmap dimensions, causing bander - a static - to point to previously freed memory instead of a newband_writer.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mupdffixed1.17.0+ds1-1package
mupdffixed1.14.0+ds1-4+deb10u3busterpackage
mupdfnot-affectedstretchpackage

Примечания

  • https://bugs.ghostscript.com/show_bug.cgi?id=702253

  • http://git.ghostscript.com/?p=mupdf.git;h=96751b25462f83d6e16a9afaf8980b0c3f979c8b

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 5 лет назад

A Use After Free vulnerability exists in Artifex Software, Inc. MuPDF library 1.17.0-rc1 and earlier when a valid page was followed by a page with invalid pixmap dimensions, causing bander - a static - to point to previously freed memory instead of a newband_writer.

CVSS3: 7.8
nvd
около 5 лет назад

A Use After Free vulnerability exists in Artifex Software, Inc. MuPDF library 1.17.0-rc1 and earlier when a valid page was followed by a page with invalid pixmap dimensions, causing bander - a static - to point to previously freed memory instead of a newband_writer.

github
больше 3 лет назад

A Use After Free vulnerability exists in Artifex Software, Inc. MuPDF library 1.17.0-rc1 and earlier when a valid page was followed by a page with invalid pixmap dimensions, causing bander - a static - to point to previously freed memory instead of a newband_writer.

suse-cvrf
больше 4 лет назад

Security update for mupdf