Описание
A vulnerability was determined in Artifex MuPDF up to 1.28.0. The impacted element is the function fz_subset_cff_for_gids of the file subset-cff.c of the component CFF Index Handler. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through a bug report but has not responded yet.
Ссылки
- Product
- ExploitMitigationThird Party Advisory
- Exploit
- ExploitMitigationThird Party AdvisoryVDB Entry
- ExploitMitigationThird Party AdvisoryVDB Entry
- Permissions RequiredVDB Entry
- ExploitMitigationThird Party Advisory
- ExploitMitigationThird Party AdvisoryVDB Entry
Уязвимые конфигурации
EPSS
3.3 Low
CVSS3
6.1 Medium
CVSS3
1.7 Low
CVSS2
Дефекты
Связанные уязвимости
A vulnerability was determined in Artifex MuPDF up to 1.28.0. The impacted element is the function fz_subset_cff_for_gids of the file subset-cff.c of the component CFF Index Handler. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through a bug report but has not responded yet.
A vulnerability was determined in Artifex MuPDF up to 1.28.0. The impacted element is the function fz_subset_cff_for_gids of the file subset-cff.c of the component CFF Index Handler. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through a bug report but has not responded yet.
A vulnerability was determined in Artifex MuPDF up to 1.28.0. The impa ...
A vulnerability was determined in Artifex MuPDF up to 1.28.0. The impacted element is the function fz_subset_cff_for_gids of the file subset-cff.c of the component CFF Index Handler. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through a bug report but has not responded yet.
EPSS
3.3 Low
CVSS3
6.1 Medium
CVSS3
1.7 Low
CVSS2