NULL Pointer Dereference in Artifex jbig2dec Library Used in MuPDF and Ghostscript
CVE-2017-9216
6.5MEDIUM
Summary
The jbig2dec library, as used in MuPDF and Ghostscript, contains a vulnerability that allows a NULL pointer dereference in the jbig2_huffman_get function located in jbig2_huffman.c. This issue can lead to a segmentation fault, causing the jbig2dec utility to crash when it attempts to process an invalid file. Users of the affected products should take precautions to avoid potential crashes and ensure that files being processed are validated properly.
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved