pdf_load_obj_stm in pdf/pdf-xref.c in Artifex MuPDF 1.12.0 could reference the object stream recursively and therefore run out of error stack, which allows remote attackers to cause a denial of service via a crafted PDF document.
The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mupdf | Artifex | 1.12.0 (including) | 1.12.0 (including) |
Mupdf | Ubuntu | artful | * |
Mupdf | Ubuntu | cosmic | * |
Mupdf | Ubuntu | esm-apps/xenial | * |
Mupdf | Ubuntu | trusty | * |
Mupdf | Ubuntu | upstream | * |
Mupdf | Ubuntu | xenial | * |