Impact
The flaw lies in the pdf_open_filter function of MuPDF’s PDF Xref Loading component. Processing a specially crafted PDF can cause a null pointer dereference, which may lead to a crash or other unintended behavior. The description states that the attack can be launched remotely and that published exploits exist. Delivering a malformed PDF can trigger the dereference, potentially compromising the integrity or stability of the application using the library.
Affected Systems
All installations of Artifex MuPDF before commit 3df1e30f9d7b77260e13bd0dbe1928ddeba8386e are affected. This includes every application or service that links against the MuPDF library, such as PDF viewers, document converters, or other software components that embed the library.
Risk and Exploitability
The CVSS score of 5.3 classifies this vulnerability as moderate. With an EPSS score of less than 1%, exploitation attempts are currently rare and the vulnerability is not listed in CISA’s KEV catalog. Nonetheless, the attack can be performed remotely by providing a malicious PDF, and published exploits are already available, so the risk remains non‑negligible for systems that consume untrusted documents.
OpenCVE Enrichment