CVE-2025-71382
⚪ Do wiadomości
Nieograniczona rekurencja w MuPDF pozwala na zdalne wywołanie odmowy usługi przez złośliwy plik EPUB.
CVSS
6.5
EPSS
0.6%
Exploit
poc
Vendor
artifex
Opis źródłowy (NVD)
MuPDF before 1.27.0-rc1 contains an uncontrolled recursion vulnerability in the EPUB CSS rendering engine that allows remote attackers to cause a denial of service by supplying a maliciously crafted EPUB file with deeply nested HTML elements and inline CSS styles. The function value_from_inheritable_property() in css-apply.c recurses through the CSS property inheritance chain without a depth limit, exhausting the process stack and causing a crash in any application using MuPDF for EPUB rendering.
dos exploit
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 6.5 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.6% |
| Opublikowano (NVD) | 2026-06-23 18:17:41 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-06 22:10:00 UTC |
Referencje
- https://bugs.ghostscript.com/show_bug.cgi?id=708840 ([email protected]) [Exploit, Issue Tracking, Mitigation]
- https://github.com/ArtifexSoftware/mupdf/commit/70b71ab22e6de4d4c44cd301c88231f623a4e94e ([email protected]) [Patch]
- https://github.com/ArtifexSoftware/mupdf/releases/tag/1.27.0-rc1 ([email protected]) [Release Notes]
- https://www.vulncheck.com/advisories/mupdf-rc1-stack-exhaustion-dos-via-epub-css-rendering ([email protected]) [Patch, Third Party Advisory]