Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-7233

Опубликовано: 28 апр. 2026
Источник: redhat
CVSS3: 3.3

Описание

A vulnerability was determined in Artifex MuPDF up to 1.28.0. The impacted element is the function fz_subset_cff_for_gids of the file subset-cff.c of the component CFF Index Handler. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through a bug report but has not responded yet.

A flaw was found in Artifex MuPDF, specifically within its CFF Index Handler component. A local user could exploit an out-of-bounds read vulnerability in the fz_subset_cff_for_gids function. This could allow an attacker to read sensitive information from memory, potentially leading to information disclosure.

Отчет

This vulnerability is rated as Low impact. The out-of-bounds read in Artifex MuPDF's CFF Index Handler requires local user access to exploit, limiting its potential for widespread impact on Red Hat systems. Successful exploitation could lead to information disclosure from memory.

Меры по смягчению последствий

Users should avoid opening untrusted or malicious PDF documents with applications that utilize the MuPDF library. If the mupdf package is not essential for system operation, consider removing it to eliminate the attack surface.

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2463367mupdf: Artifex MuPDF: Information disclosure due to out-of-bounds read

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 3.3
ubuntu
3 месяца назад

A vulnerability was determined in Artifex MuPDF up to 1.28.0. The impacted element is the function fz_subset_cff_for_gids of the file subset-cff.c of the component CFF Index Handler. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through a bug report but has not responded yet.

CVSS3: 3.3
nvd
3 месяца назад

A vulnerability was determined in Artifex MuPDF up to 1.28.0. The impacted element is the function fz_subset_cff_for_gids of the file subset-cff.c of the component CFF Index Handler. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through a bug report but has not responded yet.

CVSS3: 3.3
debian
3 месяца назад

A vulnerability was determined in Artifex MuPDF up to 1.28.0. The impa ...

CVSS3: 3.3
github
3 месяца назад

A vulnerability was determined in Artifex MuPDF up to 1.28.0. The impacted element is the function fz_subset_cff_for_gids of the file subset-cff.c of the component CFF Index Handler. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through a bug report but has not responded yet.

3.3 Low

CVSS3