MuPDF mutool
cpe:2.3:a:artifex:mupdf:*:*:*:*:*:*:*
- < commit 0f17d789fe8c29b41e47663be82514aaca3a4dfb
A vulnerability exists in MuPDF's command-line tool, mutool, which fails to properly sanitize PDF metadata before it is output to the terminal. This oversight allows attackers to inject arbitrary ANSI escape sequences through manipulated PDF metadata. When the 'mutool info' command is executed, these malicious ANSI codes are transmitted unsanitized to the terminal. This could enable attackers to clear the terminal screen and display misleading text, potentially for social engineering purposes, such as creating fake prompts or impersonating commands.
Exploitation of this vulnerability could lead to unauthorized ANSI injection, allowing for manipulation of the terminal display. This could be used to conduct social engineering attacks by presenting deceptive prompts or spoofed commands.
Users are advised to update to the latest version of MuPDF, where this vulnerability has been addressed. The patch is available in the official MuPDF repository.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.