In MuPDF 1.12.0, there is an infinite loop vulnerability and application hang in the pdf_parse_array function (pdf/pdf-parse.c) because EOF is not considered. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted pdf file.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade mupdf | Aug 22, 2024 | Jan 14, 2018 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jan 14, 2018 |
| Debian | — | Upgrade mupdf | Feb 19, 2019 | Jan 13, 2018 |
| Gentoo Linux | — | Upgrade app-text/mupdf. | Nov 27, 2018 | Jan 13, 2018 |
| Suse | — | Upgrade mupdfUpgrade mupdf-devel-static | Jan 26, 2018 | Jan 13, 2018 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Jan 14, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub