Описание
Artifex MuPDF 1.15.0 has a heap-based buffer overflow in fz_append_display_node located at fitz/list-device.c, allowing remote attackers to execute arbitrary code via a crafted PDF file. This occurs with a large BDC property name that overflows the allocated size of a display list node.
| Релиз | Статус | Примечание |
|---|---|---|
| bionic | ignored | end of standard support, was needed |
| cosmic | ignored | end of life |
| devel | released | 1.15.0+ds1-1 |
| disco | ignored | end of life |
| eoan | released | 1.15.0+ds1-1 |
| esm-apps/bionic | needed | |
| esm-apps/focal | released | 1.15.0+ds1-1 |
| esm-apps/jammy | released | 1.15.0+ds1-1 |
| esm-apps/noble | released | 1.15.0+ds1-1 |
| esm-apps/xenial | needed |
Показывать по
EPSS
6.8 Medium
CVSS2
7.8 High
CVSS3
Связанные уязвимости
Artifex MuPDF 1.15.0 has a heap-based buffer overflow in fz_append_display_node located at fitz/list-device.c, allowing remote attackers to execute arbitrary code via a crafted PDF file. This occurs with a large BDC property name that overflows the allocated size of a display list node.
Artifex MuPDF 1.15.0 has a heap-based buffer overflow in fz_append_dis ...
Artifex MuPDF 1.15.0 has a heap-based buffer overflow in fz_append_display_node located at fitz/list-device.c, allowing remote attackers to execute arbitrary code via a crafted PDF file. This occurs with a large BDC property name that overflows the allocated size of a display list node.
Уязвимость функции fz_append_display_node программы просмотра PDF-файлов Artifex MuPDF, вызванная переполнением буфера в динамической памяти, позволяющая нарушителю выполнить произвольный код
EPSS
6.8 Medium
CVSS2
7.8 High
CVSS3