Описание
pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_page.py PageObject._extract_text and PageObject.extract_xform_text to traverse a directed acyclic graph of reused form XObjects in which each form invokes a child multiple times, creating exponentially many traversal paths and causing long runtimes and large memory consumption. This issue is fixed in version 6.16.1.
EPSS
Дефекты
Связанные уязвимости
(pypdf is a free and open-source pure-python PDF library. Prior to 6.16 ...)
pypdf is a free and open-source pure-python PDF library. Prior to 6.16.1, an attacker can craft a PDF that causes pypdf/_page.py PageObject._extract_text and PageObject.extract_xform_text to traverse a directed acyclic graph of reused form XObjects in which each form invokes a child multiple times, creating exponentially many traversal paths and causing long runtimes and large memory consumption. This issue is fixed in version 6.16.1.
pypdf is a free and open-source pure-python PDF library. Prior to 6.16 ...
pypdf: Possible long runtimes/large memory usage when extracting XForm objects
Уязвимость функций PageObject._extract_text() и PageObject.extract_xform_text() библиотеки Python для работы с PDF файлами PyPDF, позволяющая нарушителю вызвать отказ в обслуживании
EPSS