A vulnerability was determined in Artifex MuPDF up to 1.28.0. The impacted element is the function fzsubsetcffforgids of the file subset-cff.c of the component CFF Index Handler. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through a bug report but has not responded yet.
{
"binaries": [
{
"binary_version": "1.25.1+ds1-7",
"binary_name": "libmupdf25.1"
},
{
"binary_version": "1.25.1+ds1-7",
"binary_name": "mupdf"
},
{
"binary_version": "1.25.1+ds1-7",
"binary_name": "mupdf-tools"
},
{
"binary_version": "1.25.1+ds1-7",
"binary_name": "python3-mupdf"
}
]
}{
"binaries": [
{
"binary_version": "1.27.0+ds1-3ubuntu2",
"binary_name": "libmupdf27.0"
},
{
"binary_version": "1.27.0+ds1-3ubuntu2",
"binary_name": "mupdf"
},
{
"binary_version": "1.27.0+ds1-3ubuntu2",
"binary_name": "mupdf-tools"
},
{
"binary_version": "1.27.0+ds1-3ubuntu2",
"binary_name": "python3-mupdf"
}
]
}