Описание
The package muhammara before 2.6.1, from 3.0.0 and before 3.1.1; all versions of package hummus are vulnerable to Denial of Service (DoS) when supplied with a maliciously crafted PDF file to be parsed.
Ссылки
- Issue TrackingThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- Issue TrackingPatchThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- Issue TrackingThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- Issue TrackingPatchThird Party Advisory
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.6.1 (исключая)
Одно из
cpe:2.3:a:muhammara_project:muhammara:*:*:*:*:*:*:*:*
cpe:2.3:a:muhammara_project:muhammara:*:*:*:*:*:*:*:*
cpe:2.3:a:muhammara_project:muhammara:3.0.0:*:*:*:*:*:*:*
cpe:2.3:a:muhammara_project:muhammara:3.1.0:*:*:*:*:*:*:*
EPSS
Процентиль: 82%
0.01723
Низкий
7.5 High
CVSS3
Дефекты
NVD-CWE-noinfo
Связанные уязвимости
CVSS3: 7.5
github
больше 3 лет назад
muhammara and hummus vulnerable to denial of service by NULL pointer dereference
EPSS
Процентиль: 82%
0.01723
Низкий
7.5 High
CVSS3
Дефекты
NVD-CWE-noinfo