libmobi before v0.10 contains a NULL pointer dereference via the component mobibuffergetpointer. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted mobi file.
{ "vanir_signatures": [ { "target": { "file": "src/index.c" }, "digest": { "line_hashes": [ "9587912500244841242761623461993484356", "325609148742769093108696337493334546979", "313274351642807138481567418773480517342", "71992697451769064556460110470947014042" ], "threshold": 0.9 }, "signature_version": "v1", "id": "CVE-2022-29788-10b0c300", "source": "https://github.com/bfabiszewski/libmobi/commit/ce0ab6586069791b1e8e2a42f44318e581c39939", "signature_type": "Line", "deprecated": false }, { "target": { "function": "mobi_trie_insert_infl", "file": "src/index.c" }, "digest": { "length": 682.0, "function_hash": "111361951981818957415269603156071108548" }, "signature_version": "v1", "id": "CVE-2022-29788-f1fccef4", "source": "https://github.com/bfabiszewski/libmobi/commit/ce0ab6586069791b1e8e2a42f44318e581c39939", "signature_type": "Function", "deprecated": false } ] }