CVE-2021-37220
MEDIUMMuPDF < 1.18.1 - Out-of-bounds Write via Cached Color Converter
Title source: llmDescription
MuPDF through 1.18.1 has an out-of-bounds write because the cached color converter does not properly consider the maximum key size of a hash table. This can, for example, be seen with crafted "mutool draw" input.
References (3)
Core 3
Core References
Exploit, Vendor Advisory x_refsource_misc
https://bugs.ghostscript.com/show_bug.cgi?id=703791
Patch x_refsource_misc
http://git.ghostscript.com/?p=mupdf.git%3Bh=f5712c9949d026e4b891b25837edd2edc166151f
Mailing List, Third Party Advisory vendor-advisory
x_refsource_fedora
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TKRMREIYUBGG2GV73CU7BJNW2Q34IP23/
Scores
CVSS v3
5.5
EPSS
0.0021
EPSS Percentile
42.7%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Details
CWE
CWE-787
Status
published
Products (2)
artifex/mupdf
< 1.18.1
fedoraproject/fedora
34
Published
Jul 21, 2021
Tracked Since
Feb 18, 2026