NULL Pointer Dereference in Artifex jbig2dec Library Used in MuPDF and Ghostscript
CVE-2017-9216

6.5MEDIUM

Key Information:

Vendor
Artifex
Status
Vendor
CVE Published:
24 May 2017

Summary

The jbig2dec library, as used in MuPDF and Ghostscript, contains a vulnerability that allows a NULL pointer dereference in the jbig2_huffman_get function located in jbig2_huffman.c. This issue can lead to a segmentation fault, causing the jbig2dec utility to crash when it attempts to process an invalid file. Users of the affected products should take precautions to avoid potential crashes and ensure that files being processed are validated properly.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.