CVE-2019-6130
published 2019-01-11CVE-2019-6130: Artifex MuPDF 1.14.0 has a SEGV in the function fz_load_page of the fitz/document.c file, as demonstrated by mutool. This is related to page-number mishandling…
PriorityP418medium5.5CVSS 3.0
AVLACLPRNUIRSUCNINAH
EPSS
1.56%
72.6th percentile
Artifex MuPDF 1.14.0 has a SEGV in the function fz_load_page of the fitz/document.c file, as demonstrated by mutool. This is related to page-number mishandling in cbz/mucbz.c, cbz/muimg.c, and svg/svg-doc.c.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| artifex | mupdf | — | — |
| artifex | mupdf | >= 0 < 1.14.0+ds1-3 | 1.14.0+ds1-3 |
| artifex | mupdf | >= 0 < 1.14.0+ds1-3 | 1.14.0+ds1-3 |
| artifex | mupdf | >= 0 < 1.14.0+ds1-3 | 1.14.0+ds1-3 |
| artifex | mupdf | >= 0 < 1.14.0+ds1-3 | 1.14.0+ds1-3 |
| debian | mupdf | < mupdf 1.14.0+ds1-3 (bookworm) | mupdf 1.14.0+ds1-3 (bookworm) |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9wxw-7hpr-92cr: Artifex MuPDF 1
ghsa_unreviewed·2022-05-13
CVE-2019-6130 [MEDIUM] CWE-118 GHSA-9wxw-7hpr-92cr: Artifex MuPDF 1
Artifex MuPDF 1.14.0 has a SEGV in the function fz_load_page of the fitz/document.c file, as demonstrated by mutool. This is related to page-number mishandling in cbz/mucbz.c, cbz/muimg.c, and svg/svg-doc.c.
OSV
CVE-2019-6130: Artifex MuPDF 1
osv·2019-01-11·CVSS 5.5
CVE-2019-6130 [MEDIUM] CVE-2019-6130: Artifex MuPDF 1
Artifex MuPDF 1.14.0 has a SEGV in the function fz_load_page of the fitz/document.c file, as demonstrated by mutool. This is related to page-number mishandling in cbz/mucbz.c, cbz/muimg.c, and svg/svg-doc.c.
Debian
CVE-2019-6130: mupdf - Artifex MuPDF 1.14.0 has a SEGV in the function fz_load_page of the fitz/documen...
vendor_debian·2019·CVSS 5.5
CVE-2019-6130 [MEDIUM] CVE-2019-6130: mupdf - Artifex MuPDF 1.14.0 has a SEGV in the function fz_load_page of the fitz/documen...
Artifex MuPDF 1.14.0 has a SEGV in the function fz_load_page of the fitz/document.c file, as demonstrated by mutool. This is related to page-number mishandling in cbz/mucbz.c, cbz/muimg.c, and svg/svg-doc.c.
Scope: local
bookworm: resolved (fixed in 1.14.0+ds1-3)
bullseye: resolved (fixed in 1.14.0+ds1-3)
forky: resolved (fixed in 1.14.0+ds1-3)
sid: resolved (fixed in 1.14.0+ds1-3)
trixie: resolved (fixed in 1.14.0+ds1-3)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-6130 mupdf: NULL pointer dereference in fz_load_page() in fitz/document.c
bugzilla·2019-01-18·CVSS 5.5
CVE-2019-6130 [MEDIUM] CVE-2019-6130 mupdf: NULL pointer dereference in fz_load_page() in fitz/document.c
CVE-2019-6130 mupdf: NULL pointer dereference in fz_load_page() in fitz/document.c
There is a SEGV in function fz_load_page of file fitz/document.c in Artifex MuPDF.This is realted to page-number mishandling in cbz/mucbz.c, cbz/muimg.c and svg/svg-doc.c.
Upstream issue:
https://bugs.ghostscript.com/show_bug.cgi?id=700446
Upstream patch:
http://git.ghostscript.com/?p=mupdf.git;h=faf47b94e24314d74907f3f6bc874105f2c962ed
Discussion:
Created python-PyMuPDF tracking bugs for this issue:
Affects: fedora-all [bug 1667323]
---
Created mupdf tracking bugs for this issue:
Affects: fedora-all [bug 1667372]
---
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs
Bugzilla
CVE-2019-6130 CVE-2019-6131 mupdf: various flaws [fedora-all]
bugzilla·2019-01-18·CVSS 5.5
CVE-2019-6130 [MEDIUM] CVE-2019-6130 CVE-2019-6131 mupdf: various flaws [fedora-all]
CVE-2019-6130 CVE-2019-6131 mupdf: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. Whil
Bugzilla
CVE-2019-6130 python-PyMuPDF: mupdf: NULL pointer deference in fz_load_page() in fitz/document.c [fedora-all]
bugzilla·2019-01-18·CVSS 5.5
CVE-2019-6130 [MEDIUM] CVE-2019-6130 python-PyMuPDF: mupdf: NULL pointer deference in fz_load_page() in fitz/document.c [fedora-all]
CVE-2019-6130 python-PyMuPDF: mupdf: NULL pointer deference in fz_load_page() in fitz/document.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue aff
http://www.securityfocus.com/bid/106558https://bugs.ghostscript.com/show_bug.cgi?id=700446https://cgit.ghostscript.com/cgi-bin/cgit.cgi/mupdf.git/commit/?id=faf47b94e24314d74907f3f6bc874105f2c962edhttps://lists.debian.org/debian-lts-announce/2019/06/msg00027.htmlhttps://lists.debian.org/debian-lts-announce/2020/07/msg00019.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CNJNEX5EW6YH5OARXXSSXW4HHC5PIBSY/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SEK2EHVNREJ7XZMFF2MXRWKIF4IBHPNE/http://www.securityfocus.com/bid/106558https://bugs.ghostscript.com/show_bug.cgi?id=700446https://lists.debian.org/debian-lts-announce/2019/06/msg00027.htmlhttps://lists.debian.org/debian-lts-announce/2020/07/msg00019.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CNJNEX5EW6YH5OARXXSSXW4HHC5PIBSY/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SEK2EHVNREJ7XZMFF2MXRWKIF4IBHPNE/
2019-01-11
Published