CVE-2021-3407
published 2021-02-23CVE-2021-3407: A flaw was found in mupdf 1.18.0. Double free of object during linearization may lead to memory corruption and other potential consequences.
PriorityP339medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
50.23%
98.8th percentile
A flaw was found in mupdf 1.18.0. Double free of object during linearization may lead to memory corruption and other potential consequences.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| artifex | mupdf | — | — |
| artifex | mupdf | — | — |
| artifex | mupdf | >= 0 < 1.17.0+ds1-1.3 | 1.17.0+ds1-1.3 |
| artifex | mupdf | >= 0 < 1.17.0+ds1-1.3 | 1.17.0+ds1-1.3 |
| artifex | mupdf | >= 0 < 1.17.0+ds1-1.3 | 1.17.0+ds1-1.3 |
| artifex | mupdf | >= 0 < 1.17.0+ds1-1.3 | 1.17.0+ds1-1.3 |
| artifex | mupdf | >= 0 < 1.7a-1ubuntu0.1~esm1 | 1.7a-1ubuntu0.1~esm1 |
| artifex | mupdf | >= 0 < 1.12.0+ds1-1ubuntu0.1~esm1 | 1.12.0+ds1-1ubuntu0.1~esm1 |
| artifex | mupdf | >= 0 < 1.16.1+ds1-1ubuntu1+esm1 | 1.16.1+ds1-1ubuntu1+esm1 |
| debian | debian_linux | — | — |
| debian | mupdf | < mupdf 1.17.0+ds1-1.3 (bookworm) | mupdf 1.17.0+ds1-1.3 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- ·Vulnerability affects mupdf version 1.18.0 specifically; the double-free occurs during PDF linearization processing. ↗
- ·Scope is local exploitation only, limiting remote attack surface. ↗
- ·Debian fix was backported to 1.17.0+ds1-1.3 across all active Debian releases (bullseye, bookworm, trixie, forky, sid); note the fixed package version is lower than the vulnerable upstream version, indicating a patch backport rather than an upgrade. ↗
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
MuPDF vulnerabilities
vendor_ubuntu·2025-10-16·CVSS 5.5
CVE-2018-16647 [MEDIUM] MuPDF vulnerabilities
Title: MuPDF vulnerabilities
Summary: Several security issues were fixed in MuPDF.
It was discovered that MuPDF incorrectly managed memory, resulting in a
memory leak. An attacker could possibly use this issue to cause a denial
of service. This issue only affected Ubuntu 18.04 LTS. (CVE-2018-1000036)
It was discovered that MuPDF could enter an infinite loop when parsing
certain PDF files. An attacker could possibly use this issue to cause a
denial of service. This issue only affected Ubuntu 18.04 LTS.
(CVE-2018-10289)
It was discovered that MuPDF incorrectly managed memory, possibly leading
to a segmentation fault. An attacker could possibly use this issue to
cause a denial of service. This issue only affected Ubuntu 18.04 LTS.
(CVE-2018-16647, CVE-2018-16648)
It was discovered that M
Debian
CVE-2021-3407: mupdf - A flaw was found in mupdf 1.18.0. Double free of object during linearization may...
vendor_debian·2021·CVSS 5.5
CVE-2021-3407 [MEDIUM] CVE-2021-3407: mupdf - A flaw was found in mupdf 1.18.0. Double free of object during linearization may...
A flaw was found in mupdf 1.18.0. Double free of object during linearization may lead to memory corruption and other potential consequences.
Scope: local
bookworm: resolved (fixed in 1.17.0+ds1-1.3)
bullseye: resolved (fixed in 1.17.0+ds1-1.3)
forky: resolved (fixed in 1.17.0+ds1-1.3)
sid: resolved (fixed in 1.17.0+ds1-1.3)
trixie: resolved (fixed in 1.17.0+ds1-1.3)
OSV
mupdf vulnerabilities
osv·2025-10-16·CVSS 5.5
CVE-2018-1000036 [MEDIUM] mupdf vulnerabilities
mupdf vulnerabilities
It was discovered that MuPDF incorrectly managed memory, resulting in a
memory leak. An attacker could possibly use this issue to cause a denial
of service. This issue only affected Ubuntu 18.04 LTS. (CVE-2018-1000036)
It was discovered that MuPDF could enter an infinite loop when parsing
certain PDF files. An attacker could possibly use this issue to cause a
denial of service. This issue only affected Ubuntu 18.04 LTS.
(CVE-2018-10289)
It was discovered that MuPDF incorrectly managed memory, possibly leading
to a segmentation fault. An attacker could possibly use this issue to
cause a denial of service. This issue only affected Ubuntu 18.04 LTS.
(CVE-2018-16647, CVE-2018-16648)
It was discovered that MuPDF contained a use-after-free vulnerability.
An attacker cou
GHSA
GHSA-5qxg-m35q-xr56: A flaw was found in mupdf 1
ghsa_unreviewed·2022-05-24
CVE-2021-3407 [MEDIUM] CWE-119 GHSA-5qxg-m35q-xr56: A flaw was found in mupdf 1
A flaw was found in mupdf 1.18.0. Double free of object during linearization may lead to memory corruption and other potential consequences.
OSV
CVE-2021-3407: A flaw was found in mupdf 1
osv·2021-02-23·CVSS 5.5
CVE-2021-3407 [MEDIUM] CVE-2021-3407: A flaw was found in mupdf 1
A flaw was found in mupdf 1.18.0. Double free of object during linearization may lead to memory corruption and other potential consequences.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://git.ghostscript.com/?p=mupdf.git%3Bh=cee7cefc610d42fd383b3c80c12cbc675443176ahttps://bugs.ghostscript.com/show_bug.cgi?id=703366https://lists.debian.org/debian-lts-announce/2021/03/msg00012.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LCADE3VSPWCGTE5BV4KL273R5VK3GDKM/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M44PNYCBL33OD7GC75XNE6CDS4VSGVWO/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZLC6MPH7YS6JPU427XOFRLF3KKZQUZJN/https://security.gentoo.org/glsa/202105-30http://git.ghostscript.com/?p=mupdf.git%3Bh=cee7cefc610d42fd383b3c80c12cbc675443176ahttps://bugs.ghostscript.com/show_bug.cgi?id=703366https://lists.debian.org/debian-lts-announce/2021/03/msg00012.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LCADE3VSPWCGTE5BV4KL273R5VK3GDKM/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/M44PNYCBL33OD7GC75XNE6CDS4VSGVWO/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZLC6MPH7YS6JPU427XOFRLF3KKZQUZJN/https://security.gentoo.org/glsa/202105-30
2021-02-23
Published