CVE-2014-2013

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
03/03/2014
Last modified:
12/04/2025

Description

Stack-based buffer overflow in the xps_parse_color function in xps/xps-common.c in MuPDF 1.3 and earlier allows remote attackers to execute arbitrary code via a large number of entries in the ContextColor value of the Fill attribute in a Path element.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:artifex:mupdf:*:*:*:*:*:*:*:* 1.3 (including)
cpe:2.3:a:artifex:mupdf:1.0:*:*:*:*:*:*:*
cpe:2.3:a:artifex:mupdf:1.1:*:*:*:*:*:*:*
cpe:2.3:a:artifex:mupdf:1.2:*:*:*:*:*:*:*