An integer overflow was discovered in pdf_read_new_xref_section in pdf/pdf-xref.c in Artifex MuPDF 1.11.
CVSS Details
- CVSS 3.0 Base Score: 7.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Oct 18, 2017 |
| Debian | — | Upgrade mupdf | Dec 5, 2017 | Oct 18, 2017 |
| Gentoo Linux | — | Upgrade app-text/mupdf. | Nov 27, 2018 | Oct 18, 2017 |
| Suse | — | Upgrade mupdfUpgrade mupdf-devel-static | Jan 26, 2018 | Oct 18, 2017 |
| Ubuntu | — | Upgrade mupdf | Nov 19, 2024 | Oct 18, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub