Описание
pypdf is a free and open-source pure-python PDF library. Prior to version 6.7.5, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires accessing a stream which uses the /ASCIIHexDecode filter. This issue has been patched in version 6.7.5.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| pypdf | fixed | 6.9.0-1 | package | |
| pypdf2 | removed | package |
Примечания
https://github.com/py-pdf/pypdf/security/advisories/GHSA-9m86-7pmv-2852
https://github.com/py-pdf/pypdf/pull/3666
Fixed by: https://github.com/py-pdf/pypdf/commit/648c627d2657447dfb1773412af05a0a5103b98f (6.7.5)
EPSS
Связанные уязвимости
pypdf is a free and open-source pure-python PDF library. Prior to version 6.7.5, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires accessing a stream which uses the /ASCIIHexDecode filter. This issue has been patched in version 6.7.5.
pypdf is a free and open-source pure-python PDF library. Prior to version 6.7.5, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires accessing a stream which uses the /ASCIIHexDecode filter. This issue has been patched in version 6.7.5.
pypdf is a free and open-source pure-python PDF library. Prior to version 6.7.5, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires accessing a stream which uses the /ASCIIHexDecode filter. This issue has been patched in version 6.7.5.
pypdf vulnerable to inefficient decoding of ASCIIHexDecode streams
EPSS