CVE-2017-14686 PUBLISHED

Artifex MuPDF 1.11 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, related to a "User Mode Write AV near NULL starting at wow64!Wow64NotifyDebugger+0x000000000000001d" on Windows. This occurs because read_zip_dir_imp in fitz/unzip.c does not check whether size fields in a ZIP entry are negative numbers.

EPSS 0.71% · 72.1th percentile

Risk Scores

EPSS Score
0.71%
72.1th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSmupdf0, 1.7a-1, *

Timeline

References

Open in Interactive Console →