CVE-2017-5896Out-of-bounds Read in Mupdf

CWE-125Out-of-bounds Read7 documents6 sources
Severity
5.5MEDIUMNVD
EPSS
0.4%
top 38.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 15
Latest updateMay 17

Description

Heap-based buffer overflow in the fz_subsample_pixmap function in fitz/pixmap.c in MuPDF 1.10a allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted image.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

Debianartifex/mupdf< 1.9a+ds1-3+3
NVDartifex/mupdf1.10

Patches

🔴Vulnerability Details

3
GHSA
GHSA-xr86-842q-jg2r: Heap-based buffer overflow in the fz_subsample_pixmap function in fitz/pixmap2022-05-17
OSV
CVE-2017-5896: Heap-based buffer overflow in the fz_subsample_pixmap function in fitz/pixmap2017-02-15
CVEList
CVE-2017-5896: Heap-based buffer overflow in the fz_subsample_pixmap function in fitz/pixmap2017-02-15

📋Vendor Advisories

1
Debian
CVE-2017-5896: mupdf - Heap-based buffer overflow in the fz_subsample_pixmap function in fitz/pixmap.c ...2017

💬Community

2
Bugzilla
CVE-2017-5896 mupdf: Heap-based buffer overflow in fz_subsample_pixmap2017-02-07
Bugzilla
CVE-2016-6525 CVE-2016-8674 CVE-2017-5896 mupdf: various flaws [fedora-all]2016-08-03
CVE-2017-5896 — Out-of-bounds Read in Artifex Mupdf | cvebase