DescriptionArtifex MuPDF before 1.16.0 has a heap-based buffer over-read in fz_chartorune in fitz/string.c because pdf/pdf-op-filter.c does not check for a missing string.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
NVD severitymedium

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
mupdf (PTS)stretch1.9a+ds1-4+deb9u4fixed
stretch (security)1.9a+ds1-4+deb9u5fixed
buster, buster (security)1.14.0+ds1-4+deb10u1fixed
bullseye, sid1.17.0+ds1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
mupdfsource(unstable)(not affected)


- mupdf <not-affected> (Vulnerable code introduced later)
Introduced by:;a=commit;h=abcb3e68670ebc2e5127953462a026fe1a5dd321 (1.16.0-rc1)
Fixed by:;a=commit;h=97096297d409ec6f206298444ba00719607e8ba8 (1.16.0)

Search for package or bug name: Reporting problems