Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-36464

Опубликовано: 27 июн. 2023
Источник: nvd
CVSS3: 6.2
CVSS3: 5.5
EPSS Низкий

Описание

pypdf is an open source, pure-python PDF library. In affected versions an attacker may craft a PDF which leads to an infinite loop if __parse_content_stream is executed. That is, for example, the case if the user extracted text from such a PDF. This issue was introduced in pull request #969 and resolved in pull request #1828. Users are advised to upgrade. Users unable to upgrade may modify the line while peek not in (b"\r", b"\n") in pypdf/generic/_data_structures.py to while peek not in (b"\r", b"\n", b"").

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:pypdf_project:pypdf:*:*:*:*:*:*:*:*
Версия до 3.9.0 (исключая)
cpe:2.3:a:pypdf2_project:pypdf2:*:*:*:*:*:*:*:*
Версия от 2.2.0 (включая)

EPSS

Процентиль: 9%
0.00031
Низкий

6.2 Medium

CVSS3

5.5 Medium

CVSS3

Дефекты

CWE-835

Связанные уязвимости

CVSS3: 6.2
ubuntu
больше 2 лет назад

pypdf is an open source, pure-python PDF library. In affected versions an attacker may craft a PDF which leads to an infinite loop if `__parse_content_stream` is executed. That is, for example, the case if the user extracted text from such a PDF. This issue was introduced in pull request #969 and resolved in pull request #1828. Users are advised to upgrade. Users unable to upgrade may modify the line `while peek not in (b"\r", b"\n")` in `pypdf/generic/_data_structures.py` to `while peek not in (b"\r", b"\n", b"")`.

CVSS3: 6.2
redhat
больше 2 лет назад

pypdf is an open source, pure-python PDF library. In affected versions an attacker may craft a PDF which leads to an infinite loop if `__parse_content_stream` is executed. That is, for example, the case if the user extracted text from such a PDF. This issue was introduced in pull request #969 and resolved in pull request #1828. Users are advised to upgrade. Users unable to upgrade may modify the line `while peek not in (b"\r", b"\n")` in `pypdf/generic/_data_structures.py` to `while peek not in (b"\r", b"\n", b"")`.

CVSS3: 6.2
debian
больше 2 лет назад

pypdf is an open source, pure-python PDF library. In affected versions ...

CVSS3: 6.2
github
больше 2 лет назад

pypdf and PyPDF2 possible Infinite Loop when a comment isn't followed by a character

CVSS3: 5.5
fstec
больше 3 лет назад

Уязвимость библиотек Python для работы с PDF файлами PyPDF и PyPDF2, связанная с выполнением цикла с недоступным условием выхода, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 9%
0.00031
Низкий

6.2 Medium

CVSS3

5.5 Medium

CVSS3

Дефекты

CWE-835