CVE-2018-6192: Artifex Mupdf

Medium severity, CVSS 5.5. EPSS: 1.8% chance of exploitation in the next 30 days.

In Artifex MuPDF 1.12.0, the pdf_read_new_xref function in pdf/pdf-xref.c allows remote attackers to cause a denial of service (segmentation violation and application crash) via a crafted pdf file.

Affected products

  • Artifex Mupdf: version 1.12.0 only
  • Debian Debian Linux: version 9.0 only

Published 2018-01-24. Last modified 2026-06-17.