CVE-2019-6131
published 2019-01-11CVE-2019-6131: svg-run.c in Artifex MuPDF 1.14.0 has infinite recursion with stack consumption in svg_run_use_symbol, svg_run_element, and svg_run_use, as demonstrated by…
PriorityP419medium5.5CVSS 3.0
AVLACLPRNUIRSUCNINAH
EPSS
1.54%
72.3th percentile
svg-run.c in Artifex MuPDF 1.14.0 has infinite recursion with stack consumption in svg_run_use_symbol, svg_run_element, and svg_run_use, as demonstrated by mutool.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| artifex | mupdf | — | — |
| artifex | mupdf | >= 0 < 1.14.0+ds1-3 | 1.14.0+ds1-3 |
| artifex | mupdf | >= 0 < 1.14.0+ds1-3 | 1.14.0+ds1-3 |
| artifex | mupdf | >= 0 < 1.14.0+ds1-3 | 1.14.0+ds1-3 |
| artifex | mupdf | >= 0 < 1.14.0+ds1-3 | 1.14.0+ds1-3 |
| debian | mupdf | < mupdf 1.14.0+ds1-3 (bookworm) | mupdf 1.14.0+ds1-3 (bookworm) |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p4v2-j6v4-fjv7: svg-run
ghsa_unreviewed·2022-05-13
CVE-2019-6131 [MEDIUM] CWE-674 GHSA-p4v2-j6v4-fjv7: svg-run
svg-run.c in Artifex MuPDF 1.14.0 has infinite recursion with stack consumption in svg_run_use_symbol, svg_run_element, and svg_run_use, as demonstrated by mutool.
OSV
CVE-2019-6131: svg-run
osv·2019-01-11·CVSS 5.5
CVE-2019-6131 [MEDIUM] CVE-2019-6131: svg-run
svg-run.c in Artifex MuPDF 1.14.0 has infinite recursion with stack consumption in svg_run_use_symbol, svg_run_element, and svg_run_use, as demonstrated by mutool.
Debian
CVE-2019-6131: mupdf - svg-run.c in Artifex MuPDF 1.14.0 has infinite recursion with stack consumption ...
vendor_debian·2019·CVSS 5.5
CVE-2019-6131 [MEDIUM] CVE-2019-6131: mupdf - svg-run.c in Artifex MuPDF 1.14.0 has infinite recursion with stack consumption ...
svg-run.c in Artifex MuPDF 1.14.0 has infinite recursion with stack consumption in svg_run_use_symbol, svg_run_element, and svg_run_use, as demonstrated by mutool.
Scope: local
bookworm: resolved (fixed in 1.14.0+ds1-3)
bullseye: resolved (fixed in 1.14.0+ds1-3)
forky: resolved (fixed in 1.14.0+ds1-3)
sid: resolved (fixed in 1.14.0+ds1-3)
trixie: resolved (fixed in 1.14.0+ds1-3)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-6130 CVE-2019-6131 mupdf: various flaws [fedora-all]
bugzilla·2019-01-18·CVSS 5.5
CVE-2019-6130 [MEDIUM] CVE-2019-6130 CVE-2019-6131 mupdf: various flaws [fedora-all]
CVE-2019-6130 CVE-2019-6131 mupdf: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. Whil
Bugzilla
CVE-2019-6131 mupdf: Stack overflow in function svg_run_element, svg_run_use_symbol, svg_run_use of file svg_run.c
bugzilla·2019-01-18·CVSS 5.5
CVE-2019-6131 [MEDIUM] CVE-2019-6131 mupdf: Stack overflow in function svg_run_element, svg_run_use_symbol, svg_run_use of file svg_run.c
CVE-2019-6131 mupdf: Stack overflow in function svg_run_element, svg_run_use_symbol, svg_run_use of file svg_run.c
There is a stack overflow bug in function svg_run_element, svg_run_use_symbol, svg_run_use of file svg_run.c in Artifex MuPDF.
Upstream Issue:
https://bugs.ghostscript.com/show_bug.cgi?id=700442
Upstream patch:
http://git.ghostscript.com/?p=mupdf.git;a=patch;h=c8f7e48ff74720a5e984ae19d978a5ab4d5dde5b
Discussion:
Created python-PyMuPDF tracking bugs for this issue:
Affects: fedora-all [bug 1667321]
---
Created mupdf tracking bugs for this issue:
Affects: fedora-all [bug 1667372]
---
ARRAY(0x558ebdc2e048)
Bugzilla
CVE-2019-6131 python-PyMuPDF: MuPDF:Stack overflow in function svg_run_element, svg_run_use_symbol, svg_run_use of file svg_run.c in MuPDF. [fedora-all]
bugzilla·2019-01-18·CVSS 5.5
CVE-2019-6131 [MEDIUM] CVE-2019-6131 python-PyMuPDF: MuPDF:Stack overflow in function svg_run_element, svg_run_use_symbol, svg_run_use of file svg_run.c in MuPDF. [fedora-all]
CVE-2019-6131 python-PyMuPDF: MuPDF:Stack overflow in function svg_run_element, svg_run_use_symbol, svg_run_use of file svg_run.c in MuPDF. [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
f
http://www.securityfocus.com/bid/106558https://bugs.ghostscript.com/show_bug.cgi?id=700442https://cgit.ghostscript.com/cgi-bin/cgit.cgi/mupdf.git/commit/?id=c8f7e48ff74720a5e984ae19d978a5ab4d5dde5bhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CNJNEX5EW6YH5OARXXSSXW4HHC5PIBSY/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SEK2EHVNREJ7XZMFF2MXRWKIF4IBHPNE/http://www.securityfocus.com/bid/106558https://bugs.ghostscript.com/show_bug.cgi?id=700442https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CNJNEX5EW6YH5OARXXSSXW4HHC5PIBSY/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SEK2EHVNREJ7XZMFF2MXRWKIF4IBHPNE/
2019-01-11
Published