Vulnerability Description
A Use After Free vulnerability exists in Artifex Software, Inc. MuPDF library 1.17.0-rc1 and earlier when a valid page was followed by a page with invalid pixmap dimensions, causing bander - a static - to point to previously freed memory instead of a newband_writer.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Artifex | Mupdf | <= 1.16.1 |
Related Weaknesses (CWE)
References
- http://git.ghostscript.com/?p=mupdf.git%3Bh=96751b25462f83d6e16a9afaf8980b0c3f97
- https://bugs.ghostscript.com/show_bug.cgi?id=702253Third Party Advisory
- http://git.ghostscript.com/?p=mupdf.git%3Bh=96751b25462f83d6e16a9afaf8980b0c3f97
- https://bugs.ghostscript.com/show_bug.cgi?id=702253Third Party Advisory
FAQ
What is CVE-2020-16600?
CVE-2020-16600 is a vulnerability with a CVSS score of 7.8 (HIGH). A Use After Free vulnerability exists in Artifex Software, Inc. MuPDF library 1.17.0-rc1 and earlier when a valid page was followed by a page with invalid pixmap dimensions, causing bander - a static ...
How severe is CVE-2020-16600?
CVE-2020-16600 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-16600?
Check the references section above for vendor advisories and patch information. Affected products include: Artifex Mupdf.