Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-46206

Опубликовано: 04 авг. 2025
Источник: debian

Описание

An issue in Artifex mupdf 1.25.6, 1.25.5 allows a remote attacker to cause a denial of service via an infinite recursion in the `mutool clean` utility. When processing a crafted PDF file containing cyclic /Next references in the outline structure, the `strip_outline()` function enters infinite recursion

Пакеты

ПакетСтатусВерсия исправленияРелизТип
mupdffixed1.25.1+ds1-7package
mupdfno-dsatrixiepackage
mupdfno-dsabookwormpackage
mupdfpostponedbullseyepackage

Примечания

  • https://bugs.ghostscript.com/show_bug.cgi?id=708521

  • Introduced after: https://cgit.ghostscript.com/cgi-bin/cgit.cgi/mupdf.git/commit/?id=dde049432d9f28d29aa4be6730e67ebc28415ef3 (1.9-rc1)

  • Fixed by: https://cgit.ghostscript.com/cgi-bin/cgit.cgi/mupdf.git/commit/?id=0ec7e4d2201bb6df217e01c17396d36297abf9ac

Связанные уязвимости

CVSS3: 6.5
ubuntu
6 месяцев назад

An issue in Artifex mupdf 1.25.6, 1.25.5 allows a remote attacker to cause a denial of service via an infinite recursion in the `mutool clean` utility. When processing a crafted PDF file containing cyclic /Next references in the outline structure, the `strip_outline()` function enters infinite recursion

CVSS3: 6.5
nvd
6 месяцев назад

An issue in Artifex mupdf 1.25.6, 1.25.5 allows a remote attacker to cause a denial of service via an infinite recursion in the `mutool clean` utility. When processing a crafted PDF file containing cyclic /Next references in the outline structure, the `strip_outline()` function enters infinite recursion

CVSS3: 7.5
github
6 месяцев назад

An issue in Artifex mupdf 1.25.6, 1.25.5 allows a remote attacker to cause a denial of service via an infinite recursion in the `mutool clean` utility. When processing a crafted PDF file containing cyclic /Next references in the outline structure, the `strip_outline()` function enters infinite recursion

CVSS3: 6.5
fstec
6 месяцев назад

Уязвимость утилиты mutool clean программы просмотра PDF-файлов MuPDF, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 6.5
redos
4 месяца назад

Уязвимость mupdf