CVE-2026-25920
EUVD-2026-626009.02.2026, 22:16
SumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, a heap out-of-bounds read vulnerability exists in SumatraPDF's MOBI HuffDic decompressor. The bounds check in AddCdicData() only validates half the range that DecodeOne() actually accesses. Opening a crafted .mobi file can read nearly (1 << codeLength) bytes beyond the CDIC dictionary buffer, leading to a crash.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| sumatrapdfreader | sumatrapdf | 𝑥 ≤ 3.5.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration