MuPDF through 1.18.1 has an out-of-bounds write because the cached color converter does not properly consider the maximum key size of a hash table. This can, for example, be seen with crafted "mutool draw" input.
References
Link | Resource |
---|---|
https://bugs.ghostscript.com/show_bug.cgi?id=703791 | Exploit Vendor Advisory |
http://git.ghostscript.com/?p=mupdf.git;h=f5712c9949d026e4b891b25837edd2edc166151f | Patch Vendor Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TKRMREIYUBGG2GV73CU7BJNW2Q34IP23/ | Patch Third Party Advisory |
Information
Published : 2021-07-21 15:15
Updated : 2021-11-28 15:19
NVD link : CVE-2021-37220
Mitre link : CVE-2021-37220
JSON object : View
CWE
CWE-787
Out-of-bounds Write
Products Affected
artifex
- mupdf
fedoraproject
- fedora