Vulnerability Description
Artifex Software mupdf v1.24.9 was discovered to contain a segmentation fault via the component /tools/pdfextract.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Artifex | Mupdf | 1.24.9 |
Related Weaknesses (CWE)
References
- https://cgit.ghostscript.com/cgi-bin/cgit.cgi/mupdf.git/diff/?id=b5c898a30f068b5Patch
- https://gist.github.com/isumitpatel/615e6bd2621cb46b5d980ddb9db223e2ExploitPatchThird Party Advisory
- https://github.com/ArtifexSoftware/mupdf/commit/b5c898a30f068b5342e8263a2cd5b9f0Patch
FAQ
What is CVE-2024-46657?
CVE-2024-46657 is a vulnerability with a CVSS score of 5.5 (MEDIUM). Artifex Software mupdf v1.24.9 was discovered to contain a segmentation fault via the component /tools/pdfextract.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafte...
How severe is CVE-2024-46657?
CVE-2024-46657 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-46657?
Check the references section above for vendor advisories and patch information. Affected products include: Artifex Mupdf.