The pdftonum function in pdf-object.c in MuPDF before 1.10 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted file.
{ "binaries": [ { "binary_name": "libmupdf-dev", "binary_version": "1.7a-1ubuntu0.1~esm1" }, { "binary_name": "mupdf", "binary_version": "1.7a-1ubuntu0.1~esm1" }, { "binary_name": "mupdf-tools", "binary_version": "1.7a-1ubuntu0.1~esm1" } ] }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2016/UBUNTU-CVE-2016-8674.json"