UBUNTU-CVE-2017-14685
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-14685
Summary:
Details: Artifex MuPDF 1.11 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .xps file, related to "Data from Faulting Address controls Branch Selection starting at mupdf+0x000000000016aa61" on Windows. This occurs because xps_load_links_in_glyphs in xps/xps-link.c does not verify that an xps font could be loaded.
References: https://ubuntu.com/security/CVE-2017-14685, http://git.ghostscript.com/?p=mupdf.git;h=ab1a420613dec93c686acbee2c165274e922f82a, https://bugs.ghostscript.com/show_bug.cgi?id=698539, https://www.cve.org/CVERecord?id=CVE-2017-14685
Affected packages
Package
Name: mupdf
Purl: pkg:deb/ubuntu/[email protected]+ds1-1?arch=source&distro=bionic
Affected ranges
Type: ECOSYSTEM
Events:
