CVE-2021-37220

MEDIUM

MuPDF < 1.18.1 - Out-of-bounds Write via Cached Color Converter

Title source: llm
STIX 2.1

Description

MuPDF through 1.18.1 has an out-of-bounds write because the cached color converter does not properly consider the maximum key size of a hash table. This can, for example, be seen with crafted "mutool draw" input.

References (3)

Core 3

Scores

CVSS v3 5.5
EPSS 0.0021
EPSS Percentile 42.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Details

CWE
CWE-787
Status published
Products (2)
artifex/mupdf < 1.18.1
fedoraproject/fedora 34
Published Jul 21, 2021
Tracked Since Feb 18, 2026