ALT-PU-2020-3484-1
Closed vulnerabilities
BDU:2021-01778
Уязвимость программы просмотра PDF-файлов MuPDf, связанная с выходом операции за допустимые границы буфера данных, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2022-01673
Уязвимость функции tiff_expand_colormap() программы просмотра PDF-файлов MuPDf, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2017-5991
An issue was discovered in Artifex MuPDF before 1912de5f08e90af1d9d0a9791f58ba3afdb9d465. The pdf_run_xobject function in pdf-op-run.c encounters a NULL pointer dereference during a Fitz fz_paint_pixmap_with_mask painting operation. Versions 1.11 and later are unaffected.
- http://git.ghostscript.com/?p=mupdf.git%3Bh=1912de5f08e90af1d9d0a9791f58ba3afdb9d465
- http://git.ghostscript.com/?p=mupdf.git%3Bh=1912de5f08e90af1d9d0a9791f58ba3afdb9d465
- DSA-3797
- DSA-3797
- 96213
- 96213
- https://bugs.ghostscript.com/show_bug.cgi?id=697500
- https://bugs.ghostscript.com/show_bug.cgi?id=697500
- GLSA-201706-08
- GLSA-201706-08
- 42138
- 42138
Modified: 2024-11-21
CVE-2018-10289
In MuPDF 1.13.0, there is an infinite loop in the fz_skip_space function of the pdf/pdf-xref.c file. A remote adversary could leverage this vulnerability to cause a denial of service via a crafted pdf file.
- http://www.ghostscript.com/cgi-bin/findgit.cgi?2e43685dc8a8a886fc9df9b3663cf199404f7637
- https://bugs.ghostscript.com/show_bug.cgi?id=699271
- https://bugs.ghostscript.com/show_bug.cgi?id=699271
- [debian-lts-announce] 20210923 [SECURITY] [DLA 2765-1] mupdf security update
- [debian-lts-announce] 20210923 [SECURITY] [DLA 2765-1] mupdf security update
Modified: 2024-11-21
CVE-2018-16647
In Artifex MuPDF 1.13.0, the pdf_get_xref_entry function in pdf/pdf-xref.c allows remote attackers to cause a denial of service (segmentation fault in fz_write_data in fitz/output.c) via a crafted pdf file.
- https://bugs.ghostscript.com/show_bug.cgi?id=699686
- https://bugs.ghostscript.com/show_bug.cgi?id=699686
- https://cgit.ghostscript.com/cgi-bin/cgit.cgi/mupdf.git/commit/?id=351c99d8ce23bbf7099dbd52771a095f67e45a2c
- [debian-lts-announce] 20200725 [SECURITY] [DLA 2289-1] mupdf security update
- [debian-lts-announce] 20200725 [SECURITY] [DLA 2289-1] mupdf security update
Modified: 2024-11-21
CVE-2018-16648
In Artifex MuPDF 1.13.0, the fz_append_byte function in fitz/buffer.c allows remote attackers to cause a denial of service (segmentation fault) via a crafted pdf file. This is caused by a pdf/pdf-device.c pdf_dev_alpha array-index underflow.
- https://bugs.ghostscript.com/show_bug.cgi?id=699685
- https://bugs.ghostscript.com/show_bug.cgi?id=699685
- https://cgit.ghostscript.com/cgi-bin/cgit.cgi/mupdf.git/commit/?id=38f883fe129a5e89306252a4676eaaf4bc968824
- [debian-lts-announce] 20200725 [SECURITY] [DLA 2289-1] mupdf security update
- [debian-lts-announce] 20200725 [SECURITY] [DLA 2289-1] mupdf security update
Modified: 2024-11-21
CVE-2019-14975
Artifex MuPDF before 1.16.0 has a heap-based buffer over-read in fz_chartorune in fitz/string.c because pdf/pdf-op-filter.c does not check for a missing string.
Modified: 2024-11-21
CVE-2020-16600
A Use After Free vulnerability exists in Artifex Software, Inc. MuPDF library 1.17.0-rc1 and earlier when a valid page was followed by a page with invalid pixmap dimensions, causing bander - a static - to point to previously freed memory instead of a newband_writer.
Modified: 2024-11-21
CVE-2020-19609
Artifex MuPDF before 1.18.0 has a heap based buffer over-write in tiff_expand_colormap() function when parsing TIFF files allowing attackers to cause a denial of service.
- http://git.ghostscript.com/?p=mupdf.git%3Bh=b7892cdc7fae62aa57d63ae62144e1f11b5f9275
- http://git.ghostscript.com/?p=mupdf.git%3Bh=b7892cdc7fae62aa57d63ae62144e1f11b5f9275
- https://bugs.ghostscript.com/show_bug.cgi?id=701176
- https://bugs.ghostscript.com/show_bug.cgi?id=701176
- https://bugs.ghostscript.com/show_bug.cgi?id=703076
- https://bugs.ghostscript.com/show_bug.cgi?id=703076
- [debian-lts-announce] 20210923 [SECURITY] [DLA 2765-1] mupdf security update
- [debian-lts-announce] 20210923 [SECURITY] [DLA 2765-1] mupdf security update
Modified: 2024-11-21
CVE-2020-26519
Artifex MuPDF before 1.18.0 has a heap based buffer over-write when parsing JBIG2 files allowing attackers to cause a denial of service.
- http://git.ghostscript.com/?p=mupdf.git%3Ba=commit%3Bh=af1e390a2c7abceb32676ec684cd1dbb92907ce8
- https://bugs.ghostscript.com/show_bug.cgi?id=702937
- [debian-lts-announce] 20210311 [SECURITY] [DLA 2589-1] mupdf security update
- FEDORA-2020-972ad7c8a8
- FEDORA-2020-3cea1ac8f3
- GLSA-202105-30
- DSA-4794
- http://git.ghostscript.com/?p=mupdf.git%3Ba=commit%3Bh=af1e390a2c7abceb32676ec684cd1dbb92907ce8
- DSA-4794
- GLSA-202105-30
- FEDORA-2020-3cea1ac8f3
- FEDORA-2020-972ad7c8a8
- [debian-lts-announce] 20210311 [SECURITY] [DLA 2589-1] mupdf security update
- https://bugs.ghostscript.com/show_bug.cgi?id=702937