漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
MuPDF < 1.27.0-rc1 Stack Exhaustion DoS via EPUB CSS Rendering
Vulnerability Description
MuPDF before 1.27.0-rc1 contains an uncontrolled recursion vulnerability in the EPUB CSS rendering engine that allows remote attackers to cause a denial of service by supplying a maliciously crafted EPUB file with deeply nested HTML elements and inline CSS styles. The function value_from_inheritable_property() in css-apply.c recurses through the CSS property inheritance chain without a depth limit, exhausting the process stack and causing a crash in any application using MuPDF for EPUB rendering.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Vulnerability Type
未经控制的递归
Vulnerability Title
ArtifexSoftware mupdf 资源管理错误漏洞
Vulnerability Description
ArtifexSoftware mupdf是ArtifexSoftware公司的一个解析PDF文档的软件。 ArtifexSoftware mupdf 1.27.0-rc1之前版本存在资源管理错误漏洞,该漏洞源于EPUB CSS渲染引擎中存在不受控制的递归,攻击者通过提供特制的EPUB文件,利用函数value_from_inheritable_property在css-apply.c中递归处理CSS属性继承链且无深度限制,耗尽进程栈,导致崩溃。
CVSS Information
N/A
Vulnerability Type
N/A