CVE-2018-19777Infinite Loop in Mupdf

CWE-835Infinite Loop7 documents6 sources
Severity
5.5MEDIUMNVD
EPSS
0.3%
top 49.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 30
Latest updateMay 13

Description

In Artifex MuPDF 1.14.0, there is an infinite loop in the function svg_dev_end_tile in fitz/svg-device.c, as demonstrated by mutool.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

Debianartifex/mupdf< 1.15.0+ds1-1+3
NVDartifex/mupdf1.14.0

Also affects: Debian Linux 8.0, 9.0

🔴Vulnerability Details

3
GHSA
GHSA-2cmx-xmf3-qm89: In Artifex MuPDF 12022-05-13
OSV
CVE-2018-19777: In Artifex MuPDF 12018-11-30
CVEList
CVE-2018-19777: In Artifex MuPDF 12018-11-30

📋Vendor Advisories

1
Debian
CVE-2018-19777: mupdf - In Artifex MuPDF 1.14.0, there is an infinite loop in the function svg_dev_end_t...2018

💬Community

2
Bugzilla
CVE-2018-19777 mupdf: infinite loop in the function svg_dev_end_tile in fitz/svg-device.c [fedora-all]2018-12-04
Bugzilla
CVE-2018-19777 mupdf: infinite loop in the function svg_dev_end_tile in fitz/svg-device.c2018-12-04
CVE-2018-19777 — Infinite Loop in Artifex Mupdf | cvebase