CVE-2016-8729 PUBLISHED

An exploitable memory corruption vulnerability exists in the JBIG2 parser of Artifex MuPDF 1.9. A specially crafted PDF can cause a negative number to be passed to a memset resulting in memory corruption and potential code execution. An attacker can specially craft a PDF and send to the victim to trigger this vulnerability.

EPSS 0.53% · 67.1th percentile

Risk Scores

EPSS Score
0.53%
67.1th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSjbig2dec0, 0.12-2, 0.12+20150918-1
Ubuntu:14.04:LTSjbig2dec0, 0.11+20120125-1ubuntu1

Timeline

References

Open in Interactive Console →