CVE-2019-13290 PUBLISHED

Artifex MuPDF 1.15.0 has a heap-based buffer overflow in fz_append_display_node located at fitz/list-device.c, allowing remote attackers to execute arbitrary code via a crafted PDF file. This occurs with a large BDC property name that overflows the allocated size of a display list node.

EPSS 1.25% · 79.2th percentile

Risk Scores

EPSS Score
1.25%
79.2th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSmupdf0
Ubuntu:Pro:16.04:LTSmupdf1.7-1, 1.7a-1, 1.7a-1ubuntu0.1~esm1
Ubuntu:Pro:18.04:LTSmupdf1.11+ds1-2, 1.12.0+ds1-1, 1.12.0+ds1-1ubuntu0.1~esm1

Timeline

References

Open in Interactive Console →