CVE-2021-3407

Name
CVE-2021-3407
Description
A flaw was found in mupdf 1.18.0. Double free of object during linearization may lead to memory corruption and other potential consequences.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Patch http://git.ghostscript.com/?p=mupdf.git;h=cee7cefc610d42fd383b3c80c12cbc675443176a
Mailing List https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/M44PNYCBL33OD7GC75XNE6CDS4VSGVWO/
Mailing List https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LCADE3VSPWCGTE5BV4KL273R5VK3GDKM/
Mailing List https://lists.debian.org/debian-lts-announce/2021/03/msg00012.html
Mailing List https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZLC6MPH7YS6JPU427XOFRLF3KKZQUZJN/
GENTOO https://security.gentoo.org/glsa/202105-30

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:artifex:mupdf:1.18.0:-:*:*:*:*:*:* mupdf == None == 1.18.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
mupdf 3.13-community 1.18.0-r1 Daniel Sabogal <dsabogalcc@gmail.com> fixed
mupdf 3.14-community 1.18.0-r1 Daniel Sabogal <dsabogalcc@gmail.com> fixed