In Artifex MuPDF 1.12.0 and earlier, multiple memory leaks in the PDF parser allow an attacker to cause a denial of service (memory leak) via a crafted file.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade mupdf | Sep 27, 2021 | May 24, 2018 |
| Gentoo Linux | — | Upgrade app-text/mupdf. | Nov 27, 2018 | May 24, 2018 |
| Ubuntu | — | Upgrade mupdf-tools (Ubuntu Pro)Upgrade libmupdf-dev (Ubuntu Pro)Upgrade mupdf (Ubuntu Pro) | Oct 21, 2025 | Oct 16, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub