CVE-2014-2013

MuPDF <1.3 - Buffer Overflow

Title source: llm

Description

Stack-based buffer overflow in the xps_parse_color function in xps/xps-common.c in MuPDF 1.3 and earlier allows remote attackers to execute arbitrary code via a large number of entries in the ContextColor value of the Fill attribute in a Path element.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Jean-Jamil Khalife · textlocalwindows
https://www.exploit-db.com/exploits/31090

Scores

EPSS 0.3447
EPSS Percentile 96.9%

Classification

CWE
CWE-119
Status draft

Affected Products (4)

artifex/mupdf < 1.3
artifex/mupdf
artifex/mupdf
artifex/mupdf

Timeline

Published Mar 03, 2014
Tracked Since Feb 18, 2026