CVE-2022-25885

HIGH7.5EPSS 0.94%

muhammara and hummus vulnerable to null pointer dereference on bad response object

Published: 11/1/2022Modified: 11/8/2023

Description

The package muhammara before 2.6.0 and the package hummus before 1.0.111 are vulnerable to Denial of Service (DoS) when PDFStreamForResponse() is used with invalid data.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References (8)