Описание
The pdf_to_num function in pdf-object.c in MuPDF before 1.10 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted file.
Ссылки
- Mailing ListPatchThird Party Advisory
- Third Party AdvisoryVDB Entry
- PatchThird Party AdvisoryVDB Entry
- Issue TrackingPatch
- Issue TrackingPatch
- Issue TrackingPatch
- Mailing ListPatchThird Party Advisory
- Third Party AdvisoryVDB Entry
- PatchThird Party AdvisoryVDB Entry
- Issue TrackingPatch
- Issue TrackingPatch
- Issue TrackingPatch
Уязвимые конфигурации
Конфигурация 1Версия до 1.9a (включая)
cpe:2.3:a:artifex:mupdf:*:*:*:*:*:*:*:*
EPSS
Процентиль: 45%
0.00225
Низкий
5.5 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-416
Связанные уязвимости
CVSS3: 5.5
ubuntu
почти 9 лет назад
The pdf_to_num function in pdf-object.c in MuPDF before 1.10 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted file.
CVSS3: 5.5
debian
почти 9 лет назад
The pdf_to_num function in pdf-object.c in MuPDF before 1.10 allows re ...
CVSS3: 5.5
github
больше 3 лет назад
The pdf_to_num function in pdf-object.c in MuPDF before 1.10 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted file.
EPSS
Процентиль: 45%
0.00225
Низкий
5.5 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-416