CVE-2018-6544 PUBLISHED

pdf_load_obj_stm in pdf/pdf-xref.c in Artifex MuPDF 1.12.0 could reference the object stream recursively and therefore run out of error stack, which allows remote attackers to cause a denial of service via a crafted PDF document.

EPSS 0.36% · 57.9th percentile

Risk Scores

EPSS Score
0.36%
57.9th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSmupdf0, 1.7-1, 1.7a-1

Timeline

References

Open in Interactive Console →