CVE-2017-17858 log
Source |
|
Severity | High |
Remote | No |
Type | Arbitrary code execution |
Description | Heap-based buffer overflow in the ensure_solid_xref function in pdf/pdf-xref.c in Artifex MuPDF 1.12.0 allows an attacker to potentially execute arbitrary code via a crafted PDF file, because xref subsection object numbers are unrestricted. |
Group | Package | Affected | Fixed | Severity | Status | Ticket |
---|---|---|---|---|---|---|
AVG-600 | zathura-pdf-mupdf | 0.3.2-1 | 0.3.2-2 | High | Fixed | |
AVG-599 | libmupdf, mupdf, mupdf-gl, mupdf-tools | 1.12.0-1 | 1.12.0-2 | High | Fixed |
Date | Advisory | Group | Package | Severity | Type |
---|---|---|---|---|---|
30 Jan 2018 | ASA-201801-31 | AVG-600 | zathura-pdf-mupdf | High | arbitrary code execution |
30 Jan 2018 | ASA-201801-30 | AVG-599 | mupdf-tools | High | arbitrary code execution |
30 Jan 2018 | ASA-201801-29 | AVG-599 | libmupdf | High | arbitrary code execution |
30 Jan 2018 | ASA-201801-28 | AVG-599 | mupdf-gl | High | arbitrary code execution |
30 Jan 2018 | ASA-201801-27 | AVG-599 | mupdf | High | arbitrary code execution |