Artifex Mupdf version 1.12.0 contains a Use After Free vulnerability in fz_keep_key_storable that can result in DOS / Possible code execution. This attack appear to be exploitable via Victim opens a specially crafted PDF.
https://www.debian.org/security/2018/dsa-4152
https://security.gentoo.org/glsa/201811-15