CVE-2022-25885

HIGH7.5EPSS 0.94%

muhammara and hummus vulnerable to null pointer dereference on bad response object

發布日:2022/11/1修改日:2023/11/8

描述

The package muhammara before 2.6.0 and the package hummus before 1.0.111 are vulnerable to Denial of Service (DoS) when PDFStreamForResponse() is used with invalid data.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

參考連結(8)