CVE-2018-1000051
published 2018-02-09CVE-2018-1000051: Artifex Mupdf version 1.12.0 contains a Use After Free vulnerability in fz_keep_key_storable that can result in DOS / Possible code execution. This attack…
PriorityP338high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
1.72%
74.8th percentile
Artifex Mupdf version 1.12.0 contains a Use After Free vulnerability in fz_keep_key_storable that can result in DOS / Possible code execution. This attack appear to be exploitable via Victim opens a specially crafted PDF.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| artifex | mupdf | — | — |
| artifex | mupdf | >= 0 < 1.12.0+ds1-1 | 1.12.0+ds1-1 |
| artifex | mupdf | >= 0 < 1.12.0+ds1-1 | 1.12.0+ds1-1 |
| artifex | mupdf | >= 0 < 1.12.0+ds1-1 | 1.12.0+ds1-1 |
| artifex | mupdf | >= 0 < 1.12.0+ds1-1 | 1.12.0+ds1-1 |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | mupdf | < mupdf 1.12.0+ds1-1 (bookworm) | mupdf 1.12.0+ds1-1 (bookworm) |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7m6m-78j4-h5p6: Artifex Mupdf version 1
ghsa_unreviewed·2022-05-14
CVE-2018-1000051 [HIGH] CWE-416 GHSA-7m6m-78j4-h5p6: Artifex Mupdf version 1
Artifex Mupdf version 1.12.0 contains a Use After Free vulnerability in fz_keep_key_storable that can result in DOS / Possible code execution. This attack appear to be exploitable via Victim opens a specially crafted PDF.
OSV
CVE-2018-1000051: Artifex Mupdf version 1
osv·2018-02-09·CVSS 7.8
CVE-2018-1000051 [HIGH] CVE-2018-1000051: Artifex Mupdf version 1
Artifex Mupdf version 1.12.0 contains a Use After Free vulnerability in fz_keep_key_storable that can result in DOS / Possible code execution. This attack appear to be exploitable via Victim opens a specially crafted PDF.
Debian
CVE-2018-1000051: mupdf - Artifex Mupdf version 1.12.0 contains a Use After Free vulnerability in fz_keep_...
vendor_debian·2018·CVSS 7.8
CVE-2018-1000051 [HIGH] CVE-2018-1000051: mupdf - Artifex Mupdf version 1.12.0 contains a Use After Free vulnerability in fz_keep_...
Artifex Mupdf version 1.12.0 contains a Use After Free vulnerability in fz_keep_key_storable that can result in DOS / Possible code execution. This attack appear to be exploitable via Victim opens a specially crafted PDF.
Scope: local
bookworm: resolved (fixed in 1.12.0+ds1-1)
bullseye: resolved (fixed in 1.12.0+ds1-1)
forky: resolved (fixed in 1.12.0+ds1-1)
sid: resolved (fixed in 1.12.0+ds1-1)
trixie: resolved (fixed in 1.12.0+ds1-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-1000051 mupdf: use-after-free in fz_keep_key_storable function [fedora-all]
bugzilla·2018-02-13·CVSS 7.8
CVE-2018-1000051 [HIGH] CVE-2018-1000051 mupdf: use-after-free in fz_keep_key_storable function [fedora-all]
CVE-2018-1000051 mupdf: use-after-free in fz_keep_key_storable function [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported v
Bugzilla
CVE-2018-1000051 mupdf: use-after-free in fz_keep_key_storable function
bugzilla·2018-02-13·CVSS 7.8
CVE-2018-1000051 [HIGH] CVE-2018-1000051 mupdf: use-after-free in fz_keep_key_storable function
CVE-2018-1000051 mupdf: use-after-free in fz_keep_key_storable function
A flaw was found in Artifex Mupdf version 1.12.0 in fz_keep_key_storable function. There is Use After Free vulnerability which can be triggered by supplying a malformed PDF file. This can result in a Denial of Service or a Possible code execution.
References:
https://bugs.ghostscript.com/show_bug.cgi?id=698825
https://bugs.ghostscript.com/show_bug.cgi?id=698873
Patch:
http://git.ghostscript.com/?p=mupdf.git;h=321ba1de287016b0036bf4a56ce774ad11763384
Discussion:
Created mupdf tracking bugs for this issue:
Affects: fedora-all [bug 1544848]
---
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the depen
https://bugs.ghostscript.com/show_bug.cgi?id=698825https://bugs.ghostscript.com/show_bug.cgi?id=698873https://cgit.ghostscript.com/cgi-bin/cgit.cgi/mupdf.git/commit/?id=321ba1de287016b0036bf4a56ce774ad11763384https://security.gentoo.org/glsa/201811-15https://www.debian.org/security/2018/dsa-4152https://bugs.ghostscript.com/show_bug.cgi?id=698825https://bugs.ghostscript.com/show_bug.cgi?id=698873https://security.gentoo.org/glsa/201811-15https://www.debian.org/security/2018/dsa-4152
2018-02-09
Published