[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250363

 
 

909

 
 

196124

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2017-14686 -- mupdf

ID: oval:org.secpod.oval:def:1901625Date: (C)2019-03-12   (M)2023-12-20
Class: VULNERABILITYFamily: unix




Artifex MuPDF 1.11 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, related to a "User Mode Write AV near NULL starting at wow64!Wow64NotifyDebugger+0x000000000000001d" on Windows. This occurs because read_zip_dir_imp in fitz/unzip.c does not check whether size fields in a ZIP entry are negative numbers.

Platform:
Ubuntu 16.04
Ubuntu 14.04
Product:
mupdf
Reference:
CVE-2017-14686
CVE    1
CVE-2017-14686
CPE    4
cpe:/o:ubuntu:ubuntu_linux:16.04
cpe:/a:artifex:mupdf
cpe:/a:artifex:mupdf:1.11
cpe:/o:ubuntu:ubuntu_linux:14.04
...

© SecPod Technologies