Описание
pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause long runtimes and large memory consumption when pypdf/_font.py function Font._collect_cid_character_widths expands unusually large CID font /W width ranges or excessive width entries during text extraction. This issue is fixed in 6.15.0.
A flaw was found in pypdf. A remote attacker could provide a specially crafted PDF file that, when processed by the Font._collect_cid_character_widths function during text extraction, causes the library to expand unusually large font width ranges. This can lead to excessive memory consumption and long processing times, resulting in a denial of service.
Отчет
This Moderate impact denial-of-service vulnerability in the pypdf library can lead to excessive memory consumption and long runtimes when processing specially crafted PDF files. This issue affects Red Hat products that handle untrusted PDF input, potentially causing service disruption due to resource exhaustion. Exploitation requires local access or a user to process a malicious PDF.
Меры по смягчению последствий
To reduce exposure, avoid processing untrusted PDF documents with applications that integrate the pypdf library. Implement robust input validation and sanitization for all PDF files originating from external or unverified sources. Consider deploying applications that process PDF content within a sandboxed environment to contain potential denial of service impacts.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Exploit Intelligence | exploit-intelligence-tech-preview/vulnerability-analysis-rhel9 | Out of support scope | ||
| Lightspeed Core | lightspeed-core/lightspeed-stack-rhel9 | Fix deferred | ||
| Lightspeed Core | lightspeed-core/rag-tool-cpu-rhel9 | Fix deferred | ||
| Lightspeed Core | lightspeed-core/rag-tool-cuda-12.9-rhel9 | Fix deferred | ||
| OpenShift Lightspeed | openshift-lightspeed/lightspeed-ocp-rag-rhel9 | Fix deferred | ||
| OpenShift Lightspeed | openshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9 | Fix deferred | ||
| Red Hat Ansible Automation Platform 2 | ansible-automation-platform-25/lightspeed-chatbot-rhel8 | Out of support scope | ||
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-cuda-rhel9 | Fix deferred | ||
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-gaudi-rhel9 | Fix deferred | ||
| Red Hat Enterprise Linux AI (RHEL AI) 3 | rhelai3/bootc-rocm-rhel9 | Fix deferred |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
5.5 Medium
CVSS3
Связанные уязвимости
pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause long runtimes and large memory consumption when pypdf/_font.py function Font._collect_cid_character_widths expands unusually large CID font /W width ranges or excessive width entries during text extraction. This issue is fixed in 6.15.0.
pypdf is a free and open-source pure-python PDF library. Prior to 6.15.0, a crafted PDF can cause long runtimes and large memory consumption when pypdf/_font.py function Font._collect_cid_character_widths expands unusually large CID font /W width ranges or excessive width entries during text extraction. This issue is fixed in 6.15.0.
pypdf is a free and open-source pure-python PDF library. Prior to 6.15 ...
pypdf: Possible long runtimes/large memory usage for large CID font width ranges
EPSS
5.5 Medium
CVSS3