CVE-2020-21896
MEDIUMArtifex MuPDF 1.16.0 - Use-After-Free in SVG Text Span Paths Definitions
Title source: llmDescription
A Use After Free vulnerability in svg_dev_text_span_as_paths_defs function in source/fitz/svg-device.c in Artifex Software MuPDF 1.16.0 allows remote attackers to cause a denial of service via opening of a crafted PDF file.
References (3)
Core 3
Core References
Exploit, Issue Tracking, Patch, Vendor Advisory
https://bugs.ghostscript.com/show_bug.cgi?id=701294
Scores
CVSS v3
5.5
EPSS
0.0021
EPSS Percentile
43.4%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-416
Status
published
Products (1)
artifex/mupdf
1.16.0
Published
Aug 22, 2023
Tracked Since
Feb 18, 2026