MuPDF v1.21.1 was discovered to contain an infinite recursion in the component pdf_mark_list_push. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.
The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.
Link | Tags |
---|---|
https://bugs.ghostscript.com/show_bug.cgi?id=706506 | permissions required |
https://git.ghostscript.com/?p=mupdf.git%3Bh=c0015401693b58e2deb5d75c39f27bc1216e47c6 | broken link |
https://gist.github.com/spookhorror/c770d118767b1b0d89fdfe2845169d06 | third party advisory |