The package muhammara before 2.6.1, from 3.0.0 and before 3.1.1; all versions of package hummus are vulnerable to Denial of Service (DoS) when supplied with a maliciously crafted PDF file to be parsed.
[
{
"signature_version": "v1",
"source": "https://github.com/julianhille/muhammarajs/commit/90b278d09f16062d93a4160ef0a54d449d739c51",
"signature_type": "Function",
"id": "CVE-2022-25892-6b47daa8",
"target": {
"function": "PDFParser::ParseLastXrefPosition",
"file": "src/deps/PDFWriter/PDFParser.cpp"
},
"digest": {
"length": 1720.0,
"function_hash": "110240482519299290359285843249292090336"
},
"deprecated": false
},
{
"signature_version": "v1",
"source": "https://github.com/julianhille/muhammarajs/commit/1890fb555eaf171db79b73fdc3ea543bbd63c002",
"signature_type": "Function",
"id": "CVE-2022-25892-730dd630",
"target": {
"function": "PDFParser::ParseLastXrefPosition",
"file": "src/deps/PDFWriter/PDFParser.cpp"
},
"digest": {
"length": 1720.0,
"function_hash": "110240482519299290359285843249292090336"
},
"deprecated": false
},
{
"signature_version": "v1",
"source": "https://github.com/julianhille/muhammarajs/commit/1890fb555eaf171db79b73fdc3ea543bbd63c002",
"signature_type": "Line",
"id": "CVE-2022-25892-8fc62d1c",
"target": {
"file": "src/deps/PDFWriter/PDFParser.cpp"
},
"digest": {
"line_hashes": [
"202187770000923064610987286081723936130",
"24389974961798006565121828465679367290",
"56621233088699263699252940820337643094"
],
"threshold": 0.9
},
"deprecated": false
},
{
"signature_version": "v1",
"source": "https://github.com/julianhille/muhammarajs/commit/90b278d09f16062d93a4160ef0a54d449d739c51",
"signature_type": "Line",
"id": "CVE-2022-25892-aa3ec95e",
"target": {
"file": "src/deps/PDFWriter/PDFParser.cpp"
},
"digest": {
"line_hashes": [
"202187770000923064610987286081723936130",
"24389974961798006565121828465679367290",
"56621233088699263699252940820337643094"
],
"threshold": 0.9
},
"deprecated": false
}
]