CVE-2025-57248 Details
Description
A null pointer dereference vulnerability was discovered in SumatraPDF 3.5.2 during the processing of a crafted .djvu file. When the file is opened, the application crashes inside libmupdf.dll, specifically in the DataPool::has_data() function.
A null pointer dereference vulnerability exists in SumatraPDF version 3.5.2, specifically within the libmupdf.dll library, when handling crafted DjVu files. The issue arises in the DataPool::has_data() function, where the application crashes due to an attempt to access data from a null pointer. This vulnerability was introduced during the parsing of a malformed DjVu file, leading to an access violation and application crash.
Users can update to the latest version of SumatraPDF, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Sep 15, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/sumatrapdfreader/sumatrapdf/issues/5035 | [email protected] | ExploitIssue TrackingPatch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-476 | NULL Pointer Dereference | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| sumatrapdfreader sumatrapdf | 3.5.2 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 20, 2025 | Initial Analysis | [email protected] |
| Sep 15, 2025 | New CVE Received | [email protected] |
| Sep 15, 2025 | CVE Modified | CISA-ADP |