CVE-2025-67432

7.5

Monkeybread Software · MBS DynaPDF Plugin

A stack overflow in the ZBarcode_Encode function of the Monkeybread Software MBS DynaPDF Plugin allows for Denial of Service via crafted input.

Executive summary

The Monkeybread Software MBS DynaPDF Plugin is vulnerable to a stack overflow flaw that can be exploited by unauthenticated attackers to trigger a Denial of Service.

Vulnerability

This vulnerability is a stack-based buffer overflow located in the ZBarcode_Encode function, which can be triggered by an unauthenticated attacker providing malicious input to the plugin.

Business impact

Successful exploitation of this flaw results in a crash of the affected service or application, leading to a Denial of Service. With a CVSS score of 7.5, this high-severity vulnerability poses a significant risk to operational availability, as the lack of authentication requirements makes the service susceptible to remote disruption by external actors.

Remediation

Immediate Action: Monitor for official security updates from Monkeybread Software and apply them as soon as a patch is released for version 21.3.1.1.

Proactive Monitoring: Review application logs for unexpected service restarts, crashes, or abnormal input patterns directed at barcode processing functions.

Compensating Controls: Implement network-level filtering or a Web Application Firewall to inspect and block malformed inputs if the plugin is exposed via a web interface.

Exploitation status

Public Exploit Available: Yes, a published PoC exists (the vulnerability is detailed in referenced GitHub Gists).

Analyst recommendation

Given the high CVSS score and the public availability of proof-of-concept material, this vulnerability should be prioritized for mitigation. IT administrators must track vendor release notes closely and deploy the necessary security patches immediately upon availability to ensure system stability and availability.

Sources