
Cloud Vulnerability DB
A community-led vulnerabilities database
A floating point exception (divide-by-zero) vulnerability was discovered in Artifex MuPDF 1.23.4 in the function fz_new_pixmap_from_float_data() of pixmap.c. The vulnerability was assigned CVE-2023-51103 and was publicly disclosed on December 26, 2023 (NVD).
The vulnerability exists in the pixmap.c file within the fz_new_pixmap_from_float_data() function. The issue occurs due to improper handling of buffer dimensions and sample calculations that could lead to a division by zero condition. The vulnerability has been assigned a CVSS v3.1 Base Score of 7.5 (HIGH) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H (NVD).
The vulnerability can lead to a denial of service condition through a floating-point exception when processing certain input files. The high CVSS score indicates significant impact on system availability, though there are no direct impacts on confidentiality or integrity (NVD).
The vulnerability has been fixed in a patch released by Artifex Software. The fix includes checks for dimensions of float sample conversion buffer and ensures that the number of samples computation does not overflow. The patch also implements consistent use of size_t instead of int for buffer sizes/indexes (Ghostscript Commit).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."