CVE-2018-18662
Publication date 26 October 2018
Last updated 17 October 2025
Ubuntu priority
Cvss 3 Severity Score
Description
There is an out-of-bounds read in fz_run_t3_glyph in fitz/font.c in Artifex MuPDF 1.14.0, as demonstrated by mutool.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| mupdf | 25.10 questing |
Not affected
|
| 24.04 LTS noble |
Not affected
|
|
| 22.04 LTS jammy |
Not affected
|
|
| 20.04 LTS focal |
Not affected
|
|
| 18.04 LTS bionic | Ignored end of standard support, was needs-triage | |
| 16.04 LTS xenial |
Not affected
|
|
| 14.04 LTS trusty | Not in release |
Notes
shishirsub10
mutool's draw feature does not exist in xenial Bionic requires 4a99615a609eec2b84bb2341d74fac46a5998137 as pre patch and due to large api changes has risk of regression
Severity score breakdown
CVSS version: CVSS v3.0
Base score
5.5 · Medium
Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H