Vulnerability Description
An exploitable memory corruption vulnerability exists in the JBIG2 parser of Artifex MuPDF 1.9. A specially crafted PDF can cause a negative number to be passed to a memset resulting in memory corruption and potential code execution. An attacker can specially craft a PDF and send to the victim to trigger this vulnerability.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Artifex | Mupdf | 1.9 |
Related Weaknesses (CWE)
References
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2016-0243Third Party Advisory
- https://bugs.ghostscript.com/show_bug.cgi?id=697395
- https://cgit.ghostscript.com/cgi-bin/cgit.cgi/jbig2dec.git/commit/?id=e698d5c11d
- https://cgit.ghostscript.com/cgi-bin/cgit.cgi/mupdf.git/commit/?id=1a7ef61410884
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2016-0243Third Party Advisory
FAQ
What is CVE-2016-8729?
CVE-2016-8729 is a vulnerability with a CVSS score of 7.8 (HIGH). An exploitable memory corruption vulnerability exists in the JBIG2 parser of Artifex MuPDF 1.9. A specially crafted PDF can cause a negative number to be passed to a memset resulting in memory corrupt...
How severe is CVE-2016-8729?
CVE-2016-8729 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-8729?
Check the references section above for vendor advisories and patch information. Affected products include: Artifex Mupdf.