CVE Published: 24/04/2018 |
CVE Updated: 16/09/2024 |
CVE Year: 2016 Source: talos |
Vendor: Artifex Software Inc. |
Product: MuPDF Status : PUBLISHED
CVE-2016-8728 Description
An exploitable heap out of bounds write vulnerability exists in the Fitz graphical library part of the MuPDF renderer. A specially crafted PDF file can cause a out of bounds write resulting in heap metadata and sensitive process memory corruption leading to potential code execution. Victim needs to open the specially crafted file in a vulnerable reader in order to trigger this vulnerability.