CVE-2018-5686: Artifex Mupdf

Medium severity, CVSS 5.5. EPSS: 1.5% chance of exploitation in the next 30 days.

In MuPDF 1.12.0, there is an infinite loop vulnerability and application hang in the pdf_parse_array function (pdf/pdf-parse.c) because EOF is not considered. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted pdf file.

Affected products

  • Artifex Mupdf: version 1.12.0 only
  • Debian Debian Linux: version 8.0 only; version 9.0 only

Published 2018-01-14. Last modified 2026-06-17.