CVE-2025-46206

An issue in Artifex mupdf 1.25.6, 1.25.5 allows a remote attacker to cause a denial of service via an infinite recursion in the `mutool clean` utility. When processing a crafted PDF file containing cyclic /Next references in the outline structure, the `strip_outline()` function enters infinite recursion
Configurations

No configuration.

History

05 Aug 2025, 17:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 6.5
CWE CWE-400 CWE-674

05 Aug 2025, 14:34

Type Values Removed Values Added
Summary
  • (es) Un problema en Artifex mupdf 1.25.6 y 1.25.5 permite a un atacante remoto provocar una denegación de servicio mediante una recursión infinita en la utilidad `mutool clean`. Al procesar un archivo PDF manipulado que contiene referencias cíclicas a /Next en la estructura del esquema, la función `strip_outline()` entra en una recursión infinita.

04 Aug 2025, 20:15

Type Values Removed Values Added
CWE CWE-400
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

04 Aug 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-04 18:15

Updated : 2025-08-05 17:15


NVD link : CVE-2025-46206

Mitre link : CVE-2025-46206

CVE.ORG link : CVE-2025-46206


JSON object : View

Products Affected

No product.

CWE
CWE-674

Uncontrolled Recursion