Improper Validation of Array Index The advisory has been revoked - it doesn't affect any version of package mupdf  (opens in a new tab)


Threat Intelligence

EPSS
0.39% (74th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UBUNTU1904-MUPDF-650293
  • published10 Sept 2020
  • disclosed6 Sept 2018

Introduced: 6 Sep 2018

CVE-2018-16648  (opens in a new tab)
CWE-129  (opens in a new tab)

Amendment

The Ubuntu security team deemed this advisory irrelevant for Ubuntu:19.04.

NVD Description

Note: Versions mentioned in the description apply only to the upstream mupdf package and not the mupdf package as distributed by Ubuntu.

In Artifex MuPDF 1.13.0, the fz_append_byte function in fitz/buffer.c allows remote attackers to cause a denial of service (segmentation fault) via a crafted pdf file. This is caused by a pdf/pdf-device.c pdf_dev_alpha array-index underflow.