CVE-2025-57248: Null Pointer Dereference
A null pointer dereference vulnerability was discovered in SumatraPDF 3.5.2 during the processing of a crafted .djvu file. When the file is opened, the application crashes inside libmupdf.dll, specifically in the DataPool::hasdata() function.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-57248?
CVE-2025-57248 has been classified with a medium severity due to its potential for causing application crashes.
How do I fix CVE-2025-57248?
To fix CVE-2025-57248, users should update SumatraPDF to the latest version or avoid opening crafted .djvu files.
What are the potential impacts of CVE-2025-57248?
The potential impacts of CVE-2025-57248 include application crashes and loss of functionality in SumatraPDF when handling specific .djvu files.
In which version of SumatraPDF does CVE-2025-57248 occur?
CVE-2025-57248 occurs in SumatraPDF version 3.5.2.
Is CVE-2025-57248 exploitable by a user?
Yes, CVE-2025-57248 is exploitable by a user who can open a specially crafted .djvu file with SumatraPDF.