CVE-2021-37220 - log back

CVE-2021-37220 edited at 11 Oct 2021 09:28:35
Description
- MuPDF through 1.18.1 has an out-of-bounds write because the cached color converter does not properly consider the maximum key size of a hash table. This can, for example, be seen with crafted "mutool draw" input.
+ MuPDF before version 1.19.0 has an out-of-bounds write because the cached color converter does not properly consider the maximum key size of a hash table. This can, for example, be seen with crafted "mutool draw" input.
CVE-2021-37220 edited at 22 Jul 2021 08:20:38
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Remote
Type
- Unknown
+ Arbitrary code execution
Description
+ MuPDF through 1.18.1 has an out-of-bounds write because the cached color converter does not properly consider the maximum key size of a hash table. This can, for example, be seen with crafted "mutool draw" input.
References
+ https://bugs.ghostscript.com/show_bug.cgi?id=703791
+ https://git.ghostscript.com/?p=mupdf.git;a=commitdiff;h=f5712c9949d026e4b891b25837edd2edc166151f
Notes
CVE-2021-37220 created at 22 Jul 2021 08:18:41