The package muhammara before 2.6.1, from 3.0.0 and before 3.1.1; all versions of package hummus are vulnerable to Denial of Service (DoS) when supplied with a maliciously crafted PDF file to be parsed.
{ "vanir_signatures": [ { "id": "CVE-2022-25892-6b47daa8", "signature_type": "Function", "digest": { "function_hash": "110240482519299290359285843249292090336", "length": 1720.0 }, "target": { "file": "src/deps/PDFWriter/PDFParser.cpp", "function": "PDFParser::ParseLastXrefPosition" }, "deprecated": false, "signature_version": "v1", "source": "https://github.com/julianhille/muhammarajs/commit/90b278d09f16062d93a4160ef0a54d449d739c51" }, { "id": "CVE-2022-25892-730dd630", "signature_type": "Function", "digest": { "function_hash": "110240482519299290359285843249292090336", "length": 1720.0 }, "target": { "file": "src/deps/PDFWriter/PDFParser.cpp", "function": "PDFParser::ParseLastXrefPosition" }, "deprecated": false, "signature_version": "v1", "source": "https://github.com/julianhille/muhammarajs/commit/1890fb555eaf171db79b73fdc3ea543bbd63c002" }, { "id": "CVE-2022-25892-8fc62d1c", "signature_type": "Line", "digest": { "line_hashes": [ "202187770000923064610987286081723936130", "24389974961798006565121828465679367290", "56621233088699263699252940820337643094" ], "threshold": 0.9 }, "target": { "file": "src/deps/PDFWriter/PDFParser.cpp" }, "deprecated": false, "signature_version": "v1", "source": "https://github.com/julianhille/muhammarajs/commit/1890fb555eaf171db79b73fdc3ea543bbd63c002" }, { "id": "CVE-2022-25892-aa3ec95e", "signature_type": "Line", "digest": { "line_hashes": [ "202187770000923064610987286081723936130", "24389974961798006565121828465679367290", "56621233088699263699252940820337643094" ], "threshold": 0.9 }, "target": { "file": "src/deps/PDFWriter/PDFParser.cpp" }, "deprecated": false, "signature_version": "v1", "source": "https://github.com/julianhille/muhammarajs/commit/90b278d09f16062d93a4160ef0a54d449d739c51" } ] }