CVE-2016-8728
published 2018-04-24CVE-2016-8728: An exploitable heap out of bounds write vulnerability exists in the Fitz graphical library part of the MuPDF renderer. A specially crafted PDF file can cause a…
PriorityP338high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
1.78%
77.3th percentile
An exploitable heap out of bounds write vulnerability exists in the Fitz graphical library part of the MuPDF renderer. A specially crafted PDF file can cause a out of bounds write resulting in heap metadata and sensitive process memory corruption leading to potential code execution. Victim needs to open the specially crafted file in a vulnerable reader in order to trigger this vulnerability.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| artifex | mupdf | — | — |
| artifex_software_inc | mupdf | — | — |
| debian | mupdf | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv3.08.6HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_debian7.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-88g7-mv6v-2x85: An exploitable heap out of bounds write vulnerability exists in the Fitz graphical library part of the MuPDF renderer
ghsa_unreviewed·2022-05-13
CVE-2016-8728 [HIGH] CWE-787 GHSA-88g7-mv6v-2x85: An exploitable heap out of bounds write vulnerability exists in the Fitz graphical library part of the MuPDF renderer
An exploitable heap out of bounds write vulnerability exists in the Fitz graphical library part of the MuPDF renderer. A specially crafted PDF file can cause a out of bounds write resulting in heap metadata and sensitive process memory corruption leading to potential code execution. Victim needs to open the specially crafted file in a vulnerable reader in order to trigger this vulnerability.
Debian
CVE-2016-8728: mupdf - An exploitable heap out of bounds write vulnerability exists in the Fitz graphic...
vendor_debian·2016·CVSS 7.8
CVE-2016-8728 [HIGH] CVE-2016-8728: mupdf - An exploitable heap out of bounds write vulnerability exists in the Fitz graphic...
An exploitable heap out of bounds write vulnerability exists in the Fitz graphical library part of the MuPDF renderer. A specially crafted PDF file can cause a out of bounds write resulting in heap metadata and sensitive process memory corruption leading to potential code execution. Victim needs to open the specially crafted file in a vulnerable reader in order to trigger this vulnerability.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-8728 CVE-2016-8729 mupdf: Multiple vulnerabilities
bugzilla·2017-05-19·CVSS 7.8
CVE-2016-8728 [HIGH] CVE-2016-8728 CVE-2016-8729 mupdf: Multiple vulnerabilities
CVE-2016-8728 CVE-2016-8729 mupdf: Multiple vulnerabilities
Two vulnerabilities in mupdf were published by Talos.
CVE-2016-8729 - Artifex MuPDf JBIG2 Parser Code Execution Vulnerability
An exploitable memory corruption vulnerability exists in the JBIG2 parser of Artifex MuPDF 1.9. A specially crafted PDF can cause a negative number to be passed to a memset resulting in memory corruption and potential code execution. An attacker can specially craft a PDF and send to the victim to trigger this vulnerability.
https://www.talosintelligence.com/vulnerability_reports/TALOS-2016-0243
CVE-2016-8728 - MuPDF Fitz library font glyph scaling Code Execution Vulnerability
An exploitable heap out of bounds write vulnerability exists in the Fitz graphical library part of the MuPDF renderer. A specia
Bugzilla
CVE-2016-8728 CVE-2016-8729 mupdf: Multiple vulnerabilities [fedora-all]
bugzilla·2017-05-19·CVSS 7.8
CVE-2016-8728 [HIGH] CVE-2016-8728 CVE-2016-8729 mupdf: Multiple vulnerabilities [fedora-all]
CVE-2016-8728 CVE-2016-8729 mupdf: Multiple vulnerabilities [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of F
2018-04-24
Published