Memory Corruption Issue in Artifex MuPDF Software
CVE-2016-8729

7.5HIGH

Key Information:

Status
Vendor
CVE Published:
24 April 2018

What is CVE-2016-8729?

A memory corruption vulnerability exists in the JBIG2 parser of Artifex MuPDF 1.9. This issue allows attackers to craft a malicious PDF that, when opened, can lead to unexpected behavior. Specifically, the vulnerability arises when a negative number is passed to a memset function, potentially resulting in memory corruption and allowing for arbitrary code execution. Users of vulnerable versions are advised to update their software to mitigate the risks associated with this flaw.

Affected Version(s)

MuPDF 1.9

MuPDF 1.10 RC2

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.