CVE-2018-1000039
published 2018-05-24CVE-2018-1000039: In Artifex MuPDF 1.12.0 and earlier, multiple heap use after free bugs in the PDF parser could allow an attacker to execute arbitrary code, read memory, or…
PriorityP336medium6.3CVSS 3.1
AVNACLPRLUINSUCLILAL
EPSS
1.85%
76.6th percentile
In Artifex MuPDF 1.12.0 and earlier, multiple heap use after free bugs in the PDF parser could allow an attacker to execute arbitrary code, read memory, or cause a denial of service via a crafted file.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| artifex | mupdf | <= 1.12.0 | — |
| artifex | mupdf | >= 0 < 1.13.0+ds1-1 | 1.13.0+ds1-1 |
| artifex | mupdf | >= 0 < 1.13.0+ds1-1 | 1.13.0+ds1-1 |
| artifex | mupdf | >= 0 < 1.13.0+ds1-1 | 1.13.0+ds1-1 |
| artifex | mupdf | >= 0 < 1.13.0+ds1-1 | 1.13.0+ds1-1 |
| debian | mupdf | < mupdf 1.13.0+ds1-1 (bookworm) | mupdf 1.13.0+ds1-1 (bookworm) |
CVSS provenance
nvdv3.16.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.3MEDIUM
vendor_debian6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mv25-m6g9-hcg7: In MuPDF 1
ghsa_unreviewed·2022-05-14
CVE-2018-1000039 [HIGH] CWE-416 GHSA-mv25-m6g9-hcg7: In MuPDF 1
In MuPDF 1.12.0 and earlier, multiple heap use after free bugs in the PDF parser could allow an attacker to execute arbitrary code, read memory, or cause a denial of service via a crafted file.
OSV
CVE-2018-1000039: In Artifex MuPDF 1
osv·2018-05-24·CVSS 6.3
CVE-2018-1000039 [MEDIUM] CVE-2018-1000039: In Artifex MuPDF 1
In Artifex MuPDF 1.12.0 and earlier, multiple heap use after free bugs in the PDF parser could allow an attacker to execute arbitrary code, read memory, or cause a denial of service via a crafted file.
Debian
CVE-2018-1000039: mupdf - In Artifex MuPDF 1.12.0 and earlier, multiple heap use after free bugs in the PD...
vendor_debian·2018·CVSS 6.3
CVE-2018-1000039 [MEDIUM] CVE-2018-1000039: mupdf - In Artifex MuPDF 1.12.0 and earlier, multiple heap use after free bugs in the PD...
In Artifex MuPDF 1.12.0 and earlier, multiple heap use after free bugs in the PDF parser could allow an attacker to execute arbitrary code, read memory, or cause a denial of service via a crafted file.
Scope: local
bookworm: resolved (fixed in 1.13.0+ds1-1)
bullseye: resolved (fixed in 1.13.0+ds1-1)
forky: resolved (fixed in 1.13.0+ds1-1)
sid: resolved (fixed in 1.13.0+ds1-1)
trixie: resolved (fixed in 1.13.0+ds1-1)
No detection rules found.
No public exploits indexed.
arXiv
Fat Pointers for Temporal Memory Safety of C
arxiv_fulltext·2023-03-20
Fat Pointers for Temporal Memory Safety of C
[Fat Pointers for Temporal Memory Safety of C]
Fat Pointers for Temporal Memory Safety of C
First1 Last1
with author1 note
nnnn-nnnn-nnnn-nnnn
Position1
Department1
Institution1
Street1 Address1
City1
State1
Post-Code1
Country1
[email protected]
First2 Last2
with author2 note
nnnn-nnnn-nnnn-nnnn
Position2a
Department2a
Institution2a
Street2a Address2a
City2a
State2a
Post-Code2a
Country2a
[email protected]
Position2b
Department2b
Institution2b
Street3b Address2b
City2b
State2b
Post-Code2b
Country2b
[email protected]
## Abstract
Temporal memory safety bugs, especially use-after-free and double free bugs,
pose a major security threat to C programs. Real-world exploits utilizing
these bugs enable
attackers to read and write arbitrary memory locations, causing disas
Bugzilla
CVE-2018-1000036 CVE-2018-1000037 CVE-2018-1000038 CVE-2018-1000039 CVE-2018-1000040 mupdf: various flaws [fedora-all]
bugzilla·2018-05-24·CVSS 5.5
CVE-2018-1000036 [MEDIUM] CVE-2018-1000036 CVE-2018-1000037 CVE-2018-1000038 CVE-2018-1000039 CVE-2018-1000040 mupdf: various flaws [fedora-all]
CVE-2018-1000036 CVE-2018-1000037 CVE-2018-1000038 CVE-2018-1000039 CVE-2018-1000040 mupdf: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this
Bugzilla
CVE-2018-1000039 mupdf: multiple use after free in the PDF parser
bugzilla·2018-05-24·CVSS 6.3
CVE-2018-1000039 [MEDIUM] CVE-2018-1000039 mupdf: multiple use after free in the PDF parser
CVE-2018-1000039 mupdf: multiple use after free in the PDF parser
In MuPDF 1.12.0 and earlier, multiple heap use after free bugs in the PDF parser could allow an attacker to execute arbitrary code, read memory, or cause a denial of service via a crafted file.
References:
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=5492
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=5513
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=5521
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=5604
Patches:
http://git.ghostscript.com/?p=mupdf.git;a=commitdiff;h=4dcc6affe04368461310a21238f7e1871a752a05;hp=8ec561d1bccc46e9db40a9f61310cd8b3763914e
http://git.ghostscript.com/?p=mupdf.git;a=commitdiff;h=71ceebcf56e682504da22c4035b39a2d451e8ffd;hp=7f82c01523505052615492f8e220f4348ba46995
http://git.ghostscript.com/?p=mupdf.git%3Ba=commitdiff%3Bh=4dcc6affe04368461310a21238f7e1871a752a05%3Bhp=8ec561d1bccc46e9db40a9f61310cd8b3763914ehttp://git.ghostscript.com/?p=mupdf.git%3Ba=commitdiff%3Bh=71ceebcf56e682504da22c4035b39a2d451e8ffd%3Bhp=7f82c01523505052615492f8e220f4348ba46995http://git.ghostscript.com/?p=mupdf.git%3Ba=commitdiff%3Bh=f597300439e62f5e921f0d7b1e880b5c1a1f1607%3Bhp=093fc3b098dc5fadef5d8ad4b225db9fb124758bhttps://bugs.chromium.org/p/oss-fuzz/issues/detail?id=5492https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=5513https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=5521https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=5604https://bugs.ghostscript.com/show_bug.cgi?id=698883https://bugs.ghostscript.com/show_bug.cgi?id=698888https://bugs.ghostscript.com/show_bug.cgi?id=698891https://bugs.ghostscript.com/show_bug.cgi?id=698892https://bugs.ghostscript.com/show_bug.cgi?id=698901https://security.gentoo.org/glsa/201811-15http://git.ghostscript.com/?p=mupdf.git%3Ba=commitdiff%3Bh=4dcc6affe04368461310a21238f7e1871a752a05%3Bhp=8ec561d1bccc46e9db40a9f61310cd8b3763914ehttp://git.ghostscript.com/?p=mupdf.git%3Ba=commitdiff%3Bh=71ceebcf56e682504da22c4035b39a2d451e8ffd%3Bhp=7f82c01523505052615492f8e220f4348ba46995http://git.ghostscript.com/?p=mupdf.git%3Ba=commitdiff%3Bh=f597300439e62f5e921f0d7b1e880b5c1a1f1607%3Bhp=093fc3b098dc5fadef5d8ad4b225db9fb124758bhttps://bugs.chromium.org/p/oss-fuzz/issues/detail?id=5492https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=5513https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=5521https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=5604https://bugs.ghostscript.com/show_bug.cgi?id=698883https://bugs.ghostscript.com/show_bug.cgi?id=698888https://bugs.ghostscript.com/show_bug.cgi?id=698891https://bugs.ghostscript.com/show_bug.cgi?id=698892https://bugs.ghostscript.com/show_bug.cgi?id=698901https://security.gentoo.org/glsa/201811-15
2018-05-24
Published