CVE-2022-25892: muhammara and hummus vulnerable to denial of service by NULL pointer dereference
The package muhammara before 2.6.1, from 3.1.0 and before 3.1.1; all versions of package hummus is vulnerable to Denial of Service (DoS) when supplied with a maliciously crafted PDF file to be parsed.
References
- github.com/advisories/GHSA-9cv5-4wqv-9w94
- github.com/galkahana/HummusJS/issues/463
- github.com/julianhille/MuhammaraJS/commit/1890fb555eaf171db79b73fdc3ea543bbd63c002
- github.com/julianhille/MuhammaraJS/commit/90b278d09f16062d93a4160ef0a54d449d739c51
- github.com/julianhille/MuhammaraJS/issues/214
- github.com/julianhille/MuhammaraJS/security/advisories/GHSA-f64j-4x74-p42m
- nvd.nist.gov/vuln/detail/CVE-2022-25892
- security.snyk.io/vuln/SNYK-JS-HUMMUS-3091138
- security.snyk.io/vuln/SNYK-JS-MUHAMMARA-3060320
Detect and mitigate CVE-2022-25892 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →