CVE-2022-25892

The package muhammara before 2.6.1, from 3.0.0 and before 3.1.1; all versions of package hummus are vulnerable to Denial of Service (DoS) when supplied with a maliciously crafted PDF file to be parsed.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:muhammara_project:muhammara:*:*:*:*:*:*:*:*
cpe:2.3:a:muhammara_project:muhammara:*:*:*:*:*:*:*:*
cpe:2.3:a:muhammara_project:muhammara:3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:muhammara_project:muhammara:3.1.0:*:*:*:*:*:*:*

History

03 Dec 2022, 02:51

Type Values Removed Values Added
CPE cpe:2.3:a:muhammara_project:muhammara:3.0.0:*:*:*:*:*:*:*

03 Nov 2022, 20:15

Type Values Removed Values Added
Summary The package muhammara before 2.6.1, from 3.1.0 and before 3.1.1; all versions of package hummus are vulnerable to Denial of Service (DoS) when supplied with a maliciously crafted PDF file to be parsed. The package muhammara before 2.6.1, from 3.0.0 and before 3.1.1; all versions of package hummus are vulnerable to Denial of Service (DoS) when supplied with a maliciously crafted PDF file to be parsed.

02 Nov 2022, 00:35

Type Values Removed Values Added
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:muhammara_project:muhammara:3.1.0:*:*:*:*:*:*:*
cpe:2.3:a:muhammara_project:muhammara:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
References (CONFIRM) https://github.com/julianhille/MuhammaraJS/commit/90b278d09f16062d93a4160ef0a54d449d739c51 - (CONFIRM) https://github.com/julianhille/MuhammaraJS/commit/90b278d09f16062d93a4160ef0a54d449d739c51 - Patch, Third Party Advisory
References (CONFIRM) https://github.com/julianhille/MuhammaraJS/issues/214 - (CONFIRM) https://github.com/julianhille/MuhammaraJS/issues/214 - Issue Tracking, Patch, Third Party Advisory
References (CONFIRM) https://github.com/julianhille/MuhammaraJS/commit/1890fb555eaf171db79b73fdc3ea543bbd63c002 - (CONFIRM) https://github.com/julianhille/MuhammaraJS/commit/1890fb555eaf171db79b73fdc3ea543bbd63c002 - Patch, Third Party Advisory
References (CONFIRM) https://security.snyk.io/vuln/SNYK-JS-MUHAMMARA-3060320 - (CONFIRM) https://security.snyk.io/vuln/SNYK-JS-MUHAMMARA-3060320 - Third Party Advisory
References (CONFIRM) https://github.com/galkahana/HummusJS/issues/463 - (CONFIRM) https://github.com/galkahana/HummusJS/issues/463 - Issue Tracking, Third Party Advisory
References (CONFIRM) https://security.snyk.io/vuln/SNYK-JS-HUMMUS-3091138 - (CONFIRM) https://security.snyk.io/vuln/SNYK-JS-HUMMUS-3091138 - Third Party Advisory

01 Nov 2022, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-11-01 05:15

Updated : 2024-02-04 22:51


NVD link : CVE-2022-25892

Mitre link : CVE-2022-25892

CVE.ORG link : CVE-2022-25892


JSON object : View

Products Affected

muhammara_project

  • muhammara