CVE-2026-26054 UNKNOWN
← Quay lại danh sách
Dịch vụ / phần mềm liên quan:
Chưa phân loại — không khớp danh sách dịch vụ/phần mềm đang theo dõi (xem/thêm ở
internal/cve/categories.go), hoặc NVD chưa cung cấp đủ dữ liệu vendor/sản phẩm cho CVE này.
⚠️ NVD chưa công bố điểm CVSS cho CVE này (thường do CVE vừa công bố, đang chờ NVD phân tích) — mức độ sẽ tự cập nhật ở lần đồng bộ sau.
Mô tả
SumatraPDF is a multi-format reader for Windows. Prior to 3.6, the MobiDoc::ParseHeader function in src/MobiDoc.cpp validates a record using kMobiHeaderMinLen but DecodeMobiDocHeader constructs a decoder sized for kMobiHeaderLen without receiving the actual remaining buffer length. A malformed MOBI file can use an attacker-controlled header length to bypass optional-field early returns and cause the decoder to read beyond a short heap buffer. Opening the crafted document can crash SumatraPDF. This issue is fixed in version 3.6.
Chi tiết
| Trạng thái | Deferred |
| Điểm CVSS | 0.0 (v) |
| Vector CVSS | |
| Ngày công bố | 00:17 25/09/2026 |
| Ngày cập nhật | 23:17 28/09/2026 |
| Nguồn dữ liệu | nvd |
CWE
Sản phẩm bị ảnh hưởng
Nguồn dữ liệu chưa cung cấp thông tin sản phẩm chi tiết.
Tài liệu tham khảo
- [security-advisories@github.com] https://github.com/sumatrapdfreader/sumatrapdf/commit/24b9ce83383bbaa48b3efe00e4d30cccea126198
- [security-advisories@github.com] https://github.com/sumatrapdfreader/sumatrapdf/issues/5318
- [security-advisories@github.com] https://github.com/sumatrapdfreader/sumatrapdf/releases/tag/3.6rel
- [security-advisories@github.com] https://github.com/sumatrapdfreader/sumatrapdf/security/advisories/GHSA-27p6-wrfp-pgm8
- [134c704f-9b21-4f2e-91b3-4a467353bcc0] https://github.com/sumatrapdfreader/sumatrapdf/security/advisories/GHSA-27p6-wrfp-pgm8
Lịch sử thay đổi
| Thời gian | Loại | Trường | Giá trị cũ | Giá trị mới |
|---|---|---|---|---|
| 23:17 28/09/2026 | CREATED | cve | UNKNOWN |