CVE-2017-14686

NameCVE-2017-14686
DescriptionArtifex MuPDF 1.11 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, related to a "User Mode Write AV near NULL starting at wow64!Wow64NotifyDebugger+0x000000000000001d" on Windows. This occurs because read_zip_dir_imp in fitz/unzip.c does not check whether size fields in a ZIP entry are negative numbers.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-4006-1
NVD severitymedium (attack range: remote)
Debian Bugs877379

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
mupdf (PTS)jessie1.5-1+deb8u4fixed
jessie (security)1.5-1+deb8u6fixed
stretch (security), stretch1.9a+ds1-4+deb9u4fixed
bullseye, buster1.14.0+ds1-4fixed
sid1.15.0+ds1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
mupdfsource(unstable)1.11+ds1-1.1medium877379
mupdfsourcejessie(not affected)
mupdfsourcestretch1.9a+ds1-4+deb9u1mediumDSA-4006-1
mupdfsourcewheezy(not affected)

Notes

[jessie] - mupdf <not-affected> (vulnerable code not present, poc not effective)
[wheezy] - mupdf <not-affected> (vulnerable code not present)
https://bugs.ghostscript.com/show_bug.cgi?id=698540
Fixed by: http://git.ghostscript.com/?p=mupdf.git;h=0f0fbc07d9be31f5e83ec5328d7311fdfd8328b1

Search for package or bug name: Reporting problems