CVE-2023-31794
MEDIUMMuPDF 1.21.1 - Denial of Service via Infinite Recursion in pdf_mark_list_push
Title source: llmDescription
MuPDF v1.21.1 was discovered to contain an infinite recursion in the component pdf_mark_list_push. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.
References (3)
Core 3
Core References
Permissions Required
https://bugs.ghostscript.com/show_bug.cgi?id=706506
Third Party Advisory
https://gist.github.com/spookhorror/c770d118767b1b0d89fdfe2845169d06
Scores
CVSS v3
5.5
EPSS
0.0024
EPSS Percentile
14.2%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-674
Status
published
Products (1)
artifex/mupdf
1.21.1
Published
Oct 31, 2023
Tracked Since
Feb 18, 2026