MuPDF 'jstest_main.c' Stack Buffer Overflow Vulnerability



MuPDF is prone to a stack-based buffer-overflow vulnerability because it fails to adequately bounds-check user-supplied data before copying it to an insufficiently sized memory buffer.

Attackers can exploit this issue to execute arbitrary code within the context of affected application or cause denial-of-service condition.

MuPDF 1.10a is affected; other versions may also be affected.

Information

Bugtraq ID: 96266
Class: Boundary Condition Error
CVE: CVE-2017-6060

Remote: Yes
Local: No
Published: Feb 16 2017 12:00AM
Updated: Jun 06 2017 07:02PM
Credit: Agostino Sarubbo of Gentoo.
Vulnerable: Gentoo Linux
Artifex Mupdf 1.10a


Not Vulnerable:

Exploit


The researcher who discovered this issue has created a proof-of-concept. Please see the references for more information.


Related Posts