Stack-based buffer overflow in the xps_parse_color function in xps/xps-common.c in MuPDF 1.3 and earlier allows remote attackers to execute arbitrary code via a large number of entries in the ContextColor value of the Fill attribute in a Path element.
CVSS Details
- CVSS 3.1 Base Score: 8.4
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade mupdf | Jul 30, 2024 | Mar 3, 2014 |
| Gentoo Linux | — | Upgrade app-text/mupdf. | Oct 30, 2017 | Mar 3, 2014 |
| Suse | — | Upgrade mupdf-debugsourceUpgrade mupdfUpgrade mupdf-devel-staticUpgrade mupdf-debuginfo | Dec 18, 2015 | Feb 28, 2014 |
| Ubuntu | — | Upgrade mupdf | Nov 19, 2024 | Mar 3, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub