Vulnerability Description
An integer overflow was discovered in pdf_read_new_xref_section in pdf/pdf-xref.c in Artifex MuPDF 1.11.
CVSS Score
7.8
HIGH
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Artifex | Mupdf | 1.11 |
Related Weaknesses (CWE)
References
- http://git.ghostscript.com/?p=mupdf.git%3Bh=82df2631d7d0446b206ea6b434ea609b6c28
- http://www.debian.org/security/2017/dsa-4006
- https://bugs.ghostscript.com/show_bug.cgi?id=698605
- https://bugs.ghostscript.com/show_bug.cgi?id=698704
- https://cgit.ghostscript.com/cgi-bin/cgit.cgi/mupdf.git/commit/?id=d18bc728e46c5
- https://lists.debian.org/debian-lts-announce/2017/11/msg00007.html
- https://security.gentoo.org/glsa/201811-15
- http://git.ghostscript.com/?p=mupdf.git%3Bh=82df2631d7d0446b206ea6b434ea609b6c28
- http://www.debian.org/security/2017/dsa-4006
- https://lists.debian.org/debian-lts-announce/2017/11/msg00007.html
- https://security.gentoo.org/glsa/201811-15
FAQ
What is CVE-2017-15587?
CVE-2017-15587 is a vulnerability with a CVSS score of 7.8 (HIGH). An integer overflow was discovered in pdf_read_new_xref_section in pdf/pdf-xref.c in Artifex MuPDF 1.11.
How severe is CVE-2017-15587?
CVE-2017-15587 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-15587?
Check the references section above for vendor advisories and patch information. Affected products include: Artifex Mupdf.