CVE Vulnerabilities

CVE-2019-6130

Incorrect Access of Indexable Resource ('Range Error')

Published: Jan 11, 2019 | Modified: Sep 11, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

Artifex MuPDF 1.14.0 has a SEGV in the function fz_load_page of the fitz/document.c file, as demonstrated by mutool. This is related to page-number mishandling in cbz/mucbz.c, cbz/muimg.c, and svg/svg-doc.c.

Weakness

The product does not restrict or incorrectly restricts operations within the boundaries of a resource that is accessed using an index or pointer, such as memory or files.

Affected Software

Name Vendor Start Version End Version
Mupdf Artifex 1.14.0 (including) 1.14.0 (including)
Mupdf Ubuntu bionic *
Mupdf Ubuntu cosmic *
Mupdf Ubuntu esm-apps/bionic *
Mupdf Ubuntu esm-apps/xenial *
Mupdf Ubuntu trusty *
Mupdf Ubuntu xenial *

References