CVE-2019-14975

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
14/08/2019
Last modified:
07/11/2023

Description

Artifex MuPDF before 1.16.0 has a heap-based buffer over-read in fz_chartorune in fitz/string.c because pdf/pdf-op-filter.c does not check for a missing string.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:artifex:mupdf:*:*:*:*:*:*:*:* 1.16.0 (excluding)