VDB
CVE-2018-1000039
CVE-2018-1000039
PUBLISHED
CVSS 6.300000190734863 MEDIUM
In Artifex MuPDF 1.12.0 and earlier, multiple heap use after free bugs in the PDF parser could allow an attacker to execute arbitrary code, read memory, or cause a denial of service via a crafted file.
EPSS 1.85% · 77.6th percentile
Risk Scores
CVSS 3.1
6.300000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
EPSS Score
1.85%
77.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:Pro:16.04:LTS | mupdf | 0, 1.7-1, 1.7a-1 |
| Ubuntu:Pro:18.04:LTS | mupdf | *, 1.12.0+ds1-1, * |
Timeline
- May 24, 2018 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Dec 28, 2021 EPSS Score
- Feb 4, 2022 EPSS Score
- Mar 1, 2022 EPSS Score
- May 2, 2022 EPSS Score
- Jul 4, 2022 EPSS Score
- Nov 8, 2022 EPSS Score
- Jan 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
References
- https://ubuntu.com/security/CVE-2018-1000039 third-party-advisory
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=5492 third-party-advisory
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=5513 third-party-advisory
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=5521 third-party-advisory
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=5604 third-party-advisory
- http://git.ghostscript.com/?p=mupdf.git;a=commitdiff;h=4dcc6affe04368461310a21238f7e1871a752a05;hp=8ec561d1bccc46e9db40a9f61310cd8b3763914e third-party-advisory
- http://git.ghostscript.com/?p=mupdf.git;a=commitdiff;h=71ceebcf56e682504da22c4035b39a2d451e8ffd;hp=7f82c01523505052615492f8e220f4348ba46995 third-party-advisory
- http://git.ghostscript.com/?p=mupdf.git;a=commitdiff;h=f597300439e62f5e921f0d7b1e880b5c1a1f1607;hp=093fc3b098dc5fadef5d8ad4b225db9fb124758b third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2018-1000039 third-party-advisory