CVE-2017-17866

pdf/pdf-write.c in Artifex MuPDF before 1.12.0 mishandles certain length changes when a repair operation occurs during a clean operation, which allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted PDF document.
Configurations

Configuration 1 (hide)

cpe:2.3:a:artifex:mupdf:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2017-12-27 17:08

Updated : 2023-12-10 12:15


NVD link : CVE-2017-17866

Mitre link : CVE-2017-17866

CVE.ORG link : CVE-2017-17866


JSON object : View

Products Affected

debian

  • debian_linux

artifex

  • mupdf
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer