Bugzilla – Bug 1188599
VUL-1: CVE-2021-37220: mupdf: out-of-bounds write because cached color converter does not properly consider the maximum key size of a hash table
Last modified: 2021-07-25 14:14:40 UTC
CVE-2021-37220 MuPDF through 1.18.1 has an out-of-bounds write because the cached color converter does not properly consider the maximum key size of a hash table. This can, for example, be seen with crafted "mutool draw" input. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-37220 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-37220 https://bugs.ghostscript.com/show_bug.cgi?id=703791 http://git.ghostscript.com/?p=mupdf.git;h=f5712c9949d026e4b891b25837edd2edc166151f