GHSA-2r7v-cmch-5x26
muhammara and hummus vulnerable to Unchecked Return Value to NULL Pointer Dereference
Quick fix
GHSA-2r7v-cmch-5x26 — muhammara: upgrade to the fixed version with the command below.
npm install muhammara@3.4.0Details
### Impact The package muhammara before 2.6.2, from 3.0.0 and before 3.3.0; all versions of package hummus are vulnerable to Denial of Service (DoS) when supplied with a maliciously crafted PDF file to be parsed.
### Patches It has been patched in 3.4.0 and has been backported to 2.6.2 There is no patch for hummus, currently
### Workarounds Do not process files from untrusted sources or update. Replace hummus with muhammara
### References https://github.com/julianhille/MuhammaraJS/pull/235 https://github.com/julianhille/MuhammaraJS/pull/238
Are you affected?
Enter the version of the package you're using.
Affected packages
0No fixed version published yet for hummus (npm). Pin to a known-safe version or switch to an alternative.
References
- https://github.com/julianhille/MuhammaraJS/security/advisories/GHSA-2r7v-cmch-5x26[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2022-41957[ADVISORY]
- https://github.com/julianhille/MuhammaraJS/pull/235[WEB]
- https://github.com/julianhille/MuhammaraJS/pull/238[WEB]
- https://github.com/julianhille/MuhammaraJS[PACKAGE]