Vulnerability Name: | CVE-2018-1000040 (CCN-143782) | ||||||||||||||||||||||||||||||||||||||||
Assigned: | 2018-01-23 | ||||||||||||||||||||||||||||||||||||||||
Published: | 2018-01-23 | ||||||||||||||||||||||||||||||||||||||||
Updated: | 2019-03-14 | ||||||||||||||||||||||||||||||||||||||||
Summary: | In MuPDF 1.12.0 and earlier, multiple use of uninitialized value bugs in the PDF parser could allow an attacker to cause a denial of service (crash) or influence program flow via a crafted file. | ||||||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 5.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H) 4.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
4.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P)
| ||||||||||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-20 | ||||||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2018-1000040 Source: CCN Type: mupdf GIT Repository Bug 698904: Upon error both free color converter and clear its pointer. Source: CONFIRM Type: Patch http://git.ghostscript.com/?p=mupdf.git;a=commitdiff;h=83d4dae44c71816c084a635550acc1a51529b881;hp=f597300439e62f5e921f0d7b1e880b5c1a1f1607 Source: MISC Type: Exploit, Issue Tracking https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=5596 Source: MISC Type: Exploit, Issue Tracking https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=5600 Source: MISC Type: Exploit, Issue Tracking https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=5603 Source: MISC Type: Exploit, Issue Tracking, Patch, Third Party Advisory https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=5609 Source: MISC Type: Exploit, Issue Tracking https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=5610 Source: XF Type: UNKNOWN mupdf-cve20181000040-dos(143782) Source: GENTOO Type: Third Party Advisory GLSA-201811-15 Source: DEBIAN Type: Third Party Advisory DSA-4334 Source: CCN Type: WhiteSource Vulnerability Database CVE-2018-1000040 | ||||||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: ![]() | ||||||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||
BACK |