Your message dated Mon, 27 Jul 2026 22:17:43 -0500
with message-id
<CAJi_FciWhyJmbCVJfDhcq6VO9NDbdJfry-v9O=4a6n3ezk8...@mail.gmail.com>
and subject line Re: mupdf: CVE-2025-55780
has caused the Debian Bug report #1116254,
regarding mupdf: CVE-2025-55780
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1116254: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1116254
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: mupdf
Version: 1.25.1+ds1-7
Severity: important
Tags: security upstream
Forwarded: https://bugs.ghostscript.com/show_bug.cgi?id=708720
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Control: found -1 1.25.1+ds1-6
Hi,
The following vulnerability was published for mupdf.
CVE-2025-55780[0]:
| A null pointer dereference occurs in the function
| break_word_for_overflow_wrap() in MuPDF 1.26.4 when rendering a
| malformed EPUB document. Specifically, the function calls
| fz_html_split_flow() to split a FLOW_WORD node, but does not check
| if node->next is valid before accessing node->next->overflow_wrap,
| resulting in a crash if the split fails or returns a partial node
| chain.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2025-55780
https://www.cve.org/CVERecord?id=CVE-2025-55780
[1] https://bugs.ghostscript.com/show_bug.cgi?id=708720
[2]
https://cgit.ghostscript.com/cgi-bin/cgit.cgi/mupdf.git/commit/?id=bdd5d241748807378a78a622388e0312332513c5
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
fixed 1116254 1.27.0+ds1-1
thanks
--
Daniel Echeverri
Debian Developer
Linux user: #477840
GPG Fingerprint:
D0D0 85B1 69C3 BFD9 4048 58FA 21FC 2950 4B52 30DB
--- End Message ---