Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-62707

Опубликовано: 22 окт. 2025
Источник: debian
EPSS Низкий

Описание

pypdf is a free and open-source pure-python PDF library. Prior to version 6.1.3, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires parsing the content stream of a page which has an inline image using the DCTDecode filter. This has been fixed in pypdf version 6.1.3.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
pypdffixed6.9.0-1package
pypdfno-dsatrixiepackage
pypdfnot-affectedbookwormpackage

Примечания

  • https://github.com/py-pdf/pypdf/security/advisories/GHSA-vr63-x8vc-m265

  • https://github.com/py-pdf/pypdf/pull/3501

  • Introduced with: https://github.com/py-pdf/pypdf/commit/23a81baad19e14ecaaa1949e52edd531b1c49efd (4.3.0)

  • Fixed by: https://github.com/py-pdf/pypdf/commit/f2864d6dd9bac7cecd3f4f54308b25ebbfa178f8 (6.1.3)

EPSS

Процентиль: 34%
0.00411
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
10 месяцев назад

pypdf is a free and open-source pure-python PDF library. Prior to version 6.1.3, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires parsing the content stream of a page which has an inline image using the DCTDecode filter. This has been fixed in pypdf version 6.1.3.

CVSS3: 5.3
redhat
10 месяцев назад

pypdf is a free and open-source pure-python PDF library. Prior to version 6.1.3, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires parsing the content stream of a page which has an inline image using the DCTDecode filter. This has been fixed in pypdf version 6.1.3.

CVSS3: 7.5
nvd
10 месяцев назад

pypdf is a free and open-source pure-python PDF library. Prior to version 6.1.3, an attacker who uses this vulnerability can craft a PDF which leads to an infinite loop. This requires parsing the content stream of a page which has an inline image using the DCTDecode filter. This has been fixed in pypdf version 6.1.3.

github
10 месяцев назад

pypdf possibly loops infinitely when reading DCT inline images without EOF marker

CVSS3: 7.5
fstec
10 месяцев назад

Уязвимость библиотеки для обработки PDF PyPDF2, связанная с чрезмерным итерированием, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 34%
0.00411
Низкий
Уязвимость CVE-2025-62707