CVE-2025-46206: Medium severity Artifex Mupdf vulnerability
An issue in Artifex mupdf 1.25.6, 1.25.5 allows a remote attacker to cause a denial of service via an infinite recursion in the mutool clean utility. When processing a crafted PDF file containing cyclic /Next references in the outline structure, the stripoutline() function enters infinite recursion
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-46206?
CVE-2025-46206 has a medium severity level due to its potential to cause denial of service.
How do I fix CVE-2025-46206?
To fix CVE-2025-46206, you should upgrade to the latest version of Artifex mupdf that resolves the infinite recursion vulnerability.
What is the impact of CVE-2025-46206 on my system?
The impact of CVE-2025-46206 is that a remote attacker could exploit the vulnerability to crash the mupdf application, leading to service disruption.
Who is affected by CVE-2025-46206?
CVE-2025-46206 affects users of Artifex mupdf versions 1.25.6 and 1.25.5 processing specially crafted PDF files.
Can CVE-2025-46206 be exploited remotely?
Yes, CVE-2025-46206 can be exploited remotely through malicious PDF files that contain cyclic /Next references.