CVE-2020-16600

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
09/12/2020
Last modified:
07/11/2023

Description

A Use After Free vulnerability exists in Artifex Software, Inc. MuPDF library 1.17.0-rc1 and earlier when a valid page was followed by a page with invalid pixmap dimensions, causing bander - a static - to point to previously freed memory instead of a newband_writer.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:artifex:mupdf:*:*:*:*:*:*:*:* 1.16.1 (including)
cpe:2.3:a:artifex:mupdf:1.17.0:rc1:*:*:*:*:*:*