Candidate: CVE-2018-1000038 PublicDate: 2018-05-24 13:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1000038 https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=5494 http://git.ghostscript.com/?p=mupdf.git;a=commitdiff;h=71ceebcf56e682504da22c4035b39a2d451e8ffd;hp=7f82c01523505052615492f8e220f4348ba46995 http://git.ghostscript.com/?p=mupdf.git;a=commitdiff;h=f597300439e62f5e921f0d7b1e880b5c1a1f1607;hp=093fc3b098dc5fadef5d8ad4b225db9fb124758b Description: In MuPDF 1.12.0 and earlier, a stack buffer overflow in function pdf_lookup_cmap_full in pdf/pdf-cmap.c could allow an attacker to execute arbitrary code via a crafted file. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [7.8 HIGH] Patches_mupdf: upstream_mupdf: released (1.13.0+ds1-1) precise/esm_mupdf: DNE trusty_mupdf: ignored (reached end-of-life) trusty/esm_mupdf: DNE (trusty was needs-triage) xenial_mupdf: ignored (end of standard support, was needs-triage) artful_mupdf: ignored (reached end-of-life) bionic_mupdf: needs-triage cosmic_mupdf: not-affected (1.13.0+ds1-1) disco_mupdf: not-affected (1.13.0+ds1-1) eoan_mupdf: not-affected (1.13.0+ds1-1) focal_mupdf: not-affected (1.13.0+ds1-1) groovy_mupdf: not-affected (1.13.0+ds1-1) hirsute_mupdf: not-affected (1.13.0+ds1-1) impish_mupdf: not-affected (1.13.0+ds1-1) jammy_mupdf: not-affected (1.13.0+ds1-1) devel_mupdf: not-affected (1.13.0+ds1-1)