CVE-2019-7321Out-of-bounds Write in Mupdf

Severity
9.8CRITICALNVD
EPSS
2.6%
top 14.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 13
Latest updateMay 24

Description

Usage of an uninitialized variable in the function fz_load_jpeg in Artifex MuPDF 1.14 can result in a heap overflow vulnerability that allows an attacker to execute arbitrary code.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages1 packages

NVDartifex/mupdf1.14.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-h4r8-57xx-v3q2: Usage of an uninitialized variable in the function fz_load_jpeg in Artifex MuPDF 12022-05-24
CVEList
CVE-2019-7321: Usage of an uninitialized variable in the function fz_load_jpeg in Artifex MuPDF 12019-06-13

📋Vendor Advisories

1
Debian
CVE-2019-7321: mupdf - Usage of an uninitialized variable in the function fz_load_jpeg in Artifex MuPDF...2019

💬Community

2
Bugzilla
CVE-2019-7321 mupdf: heap overflow in function fz_load_jpeg2019-06-19
Bugzilla
CVE-2019-7321 mupdf: heap overflow in function fz_load_jpeg [fedora-all]2019-06-19
CVE-2019-7321 — Out-of-bounds Write in Artifex Mupdf | cvebase