CVE-2018-6187Out-of-bounds Write in Mupdf

Severity
5.5MEDIUMNVD
EPSS
0.5%
top 36.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 24
Latest updateMay 13

Description

In Artifex MuPDF 1.12.0, there is a heap-based buffer overflow vulnerability in the do_pdf_save_document function in the pdf/pdf-write.c file. Remote attackers could leverage the vulnerability to cause a denial of service via a crafted pdf file.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

Debianartifex/mupdf< 1.13.0+ds1-1+3
NVDartifex/mupdf1.12.0

Also affects: Debian Linux 9.0

🔴Vulnerability Details

3
GHSA
GHSA-54h4-vpfg-6425: In Artifex MuPDF 12022-05-13
CVEList
CVE-2018-6187: In Artifex MuPDF 12018-01-24
OSV
CVE-2018-6187: In Artifex MuPDF 12018-01-24

📋Vendor Advisories

1
Debian
CVE-2018-6187: mupdf - In Artifex MuPDF 1.12.0, there is a heap-based buffer overflow vulnerability in ...2018

💬Community

2
Bugzilla
CVE-2018-6187 mupdf: heap-based buffer overflow in pdf/pdf-write.c:do_pdf_save_document() [fedora-all]2018-01-25
Bugzilla
CVE-2018-6187 mupdf: heap-based buffer overflow in pdf/pdf-write.c:do_pdf_save_document()2018-01-25
CVE-2018-6187 — Out-of-bounds Write in Artifex Mupdf | cvebase