CVE-2017-5991 describes a NULL pointer dereference vulnerability in Artifex MuPDF versions prior to 1.11, specifically within the pdf_run_xobject function during a Fitz fz_paint_pixmap_with_mask operation. This flaw affects Artifex MuPDF and Debian Linux distributions utilizing the vulnerable MuPDF versions. Rated with a CVSS score of 7.5 (High), this vulnerability is remotely exploitable with low attack complexity, requiring no user interaction or privileges, and can lead to a denial of service (system crash or unresponsiveness). While not listed on the CISA KEV catalog or showing active exploitation, public exploit code (EDB-42138) is available, and its EPSS score indicates a higher-than-average likelihood of exploitation. There is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.11CPE matchmatch criteria | cpe:2.3:a:artifex:mupdf:*:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.