muhammara and hummus vulnerable to denial of service by NULL pointer dereference
High severity
GitHub Reviewed
Published
Nov 1, 2022
to the GitHub Advisory Database
•
Updated Jan 31, 2023
Description
Published by the National Vulnerability Database
Nov 1, 2022
Published to the GitHub Advisory Database
Nov 1, 2022
Reviewed
Nov 1, 2022
Last updated
Jan 31, 2023
Impact
The package muhammara before 2.6.1, from 3.0.0 and before 3.1.1; all versions of package hummus are vulnerable to Denial of Service (DoS) when supplied with a maliciously crafted PDF file to be parsed.
Patches
It has been patched in 3.1.1 and has been backported to 2.6.1
Hummus has a patch in 1.0.111.
Workarounds
Do not process files from untrusted sources or update.
References
https://nvd.nist.gov/vuln/detail/CVE-2022-25892
galkahana/HummusJS#463
julianhille/MuhammaraJS#214
julianhille/MuhammaraJS@1890fb5
julianhille/MuhammaraJS@90b278d
https://security.snyk.io/vuln/SNYK-JS-HUMMUS-3091138
https://security.snyk.io/vuln/SNYK-JS-MUHAMMARA-3060320
References