CVE-2018-10289 (NVD)

2018-04-22

In MuPDF 1.13.0, there is an infinite loop in the fz_skip_space function of the pdf/pdf-xref.c file. A remote adversary could leverage this vulnerability to cause a denial of service via a crafted pdf file.

Products Mupdf, Debian_linux
Type Loop with Unreachable Exit Condition ('Infinite Loop') (CWE-835)
First patch - None (likely due to unavailable code)
Links https://bugs.ghostscript.com/show_bug.cgi?id=699271
https://lists.debian.org/debian-lts-announce/2021/09/msg00013.html