Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2r7v-cmch-5x26

Опубликовано: 05 дек. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

muhammara and hummus vulnerable to Unchecked Return Value to NULL Pointer Dereference

Impact

The package muhammara before 2.6.2, from 3.0.0 and before 3.3.0; all versions of package hummus are vulnerable to Denial of Service (DoS) when supplied with a maliciously crafted PDF file to be parsed.

Patches

It has been patched in 3.4.0 and has been backported to 2.6.2 There is no patch for hummus, currently

Workarounds

Do not process files from untrusted sources or update. Replace hummus with muhammara

References

https://github.com/julianhille/MuhammaraJS/pull/235 https://github.com/julianhille/MuhammaraJS/pull/238

Пакеты

Наименование

hummus

npm
Затронутые версииВерсия исправления

Отсутствует

Наименование

muhammara

npm
Затронутые версииВерсия исправления

>= 3.0.0, < 3.4.0

3.4.0

Наименование

muhammara

npm
Затронутые версииВерсия исправления

< 2.6.2

2.6.2

EPSS

Процентиль: 57%
0.00348
Низкий

7.5 High

CVSS3

Дефекты

CWE-690

Связанные уязвимости

CVSS3: 7.5
nvd
около 3 лет назад

Muhammara is a node module with c/cpp bindings to modify PDF with JavaScript for node or electron. The package muhammara before 2.6.2 and from 3.0.0 and before 3.3.0, as well as all versions of muhammara's predecessor package hummus, are vulnerable to Denial of Service (DoS) when supplied with a maliciously crafted PDF file to be parsed. The issue has been patched in muhammara version 3.4.0 and the fix has been backported to version 2.6.2. As a workaround, do not process files from untrusted sources. If using hummus, replace the package with muhammara.

EPSS

Процентиль: 57%
0.00348
Низкий

7.5 High

CVSS3

Дефекты

CWE-690