CVE-2017-5991

Name
CVE-2017-5991
Description
An issue was discovered in Artifex MuPDF before 1912de5f08e90af1d9d0a9791f58ba3afdb9d465. The pdf_run_xobject function in pdf-op-run.c encounters a NULL pointer dereference during a Fitz fz_paint_pixmap_with_mask painting operation. Versions 1.11 and later are unaffected.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
cve@mitre.org http://git.ghostscript.com/?p=mupdf.git%3Bh=1912de5f08e90af1d9d0a9791f58ba3afdb9d465
Third Party Advisory http://www.debian.org/security/2017/dsa-3797
Broken Link http://www.securityfocus.com/bid/96213
Exploit https://bugs.ghostscript.com/show_bug.cgi?id=697500
Third Party Advisory https://security.gentoo.org/glsa/201706-08
Exploit https://www.exploit-db.com/exploits/42138/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:artifex:mupdf:*:*:*:*:*:*:*:* mupdf >= None < 1.11

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
mupdf edge-community 1.10a-r2 None fixed
mupdf edge-community 1.10a-r1 None possibly vulnerable
mupdf 3.22-community 1.10a-r2 None fixed
mupdf 3.22-community 1.10a-r1 None possibly vulnerable
mupdf 3.21-community 1.10a-r2 None fixed
mupdf 3.20-community 1.10a-r2 None fixed
mupdf 3.19-community 1.10a-r2 None fixed
mupdf 3.18-community 1.10a-r2 None fixed
mupdf 3.17-community 1.10a-r2 None fixed
mupdf 3.11-main 1.10a-r2 None fixed
mupdf 3.10-main 1.10a-r2 None fixed