CVE-2018-16647

MEDIUM

Artifex MuPDF 1.13.0 - Denial of Service via Crafted PDF File

Title source: llm
STIX 2.1

Description

In Artifex MuPDF 1.13.0, the pdf_get_xref_entry function in pdf/pdf-xref.c allows remote attackers to cause a denial of service (segmentation fault in fz_write_data in fitz/output.c) via a crafted pdf file.

Scores

CVSS v3 5.5
EPSS 0.0029
EPSS Percentile 51.9%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Details

CWE
CWE-119
Status published
Products (1)
artifex/mupdf 1.13.0
Published Sep 06, 2018
Tracked Since Feb 18, 2026