Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Artifex MuPDF CFF Index subset-cff.c fz_subset_cff_for_gids out-of-bounds
Vulnerability Description
A vulnerability was determined in Artifex MuPDF up to 1.28.0. The impacted element is the function fz_subset_cff_for_gids of the file subset-cff.c of the component CFF Index Handler. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through a bug report but has not responded yet.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
跨界内存读
Vulnerability Title
Artifex Software MuPDF 缓冲区错误漏洞
Vulnerability Description
Artifex Software MuPDF是美国Artifex Software公司的一款免费的、轻量级的PDF阅读器。 Artifex Software MuPDF 1.28.0及之前版本存在缓冲区错误漏洞,该漏洞源于CFF Index Handler组件中subset-cff.c文件的fz_subset_cff_for_gids函数存在越界读取,可能导致本地攻击。
CVSS Information
N/A
Vulnerability Type
N/A