Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-66019

Опубликовано: 26 нояб. 2025
Источник: ubuntu
Приоритет: medium
EPSS Низкий

Описание

pypdf is a free and open-source pure-python PDF library. Prior to version 6.4.0, an attacker who uses this vulnerability can craft a PDF which leads to a memory usage of up to 1 GB per stream. This requires parsing the content stream of a page using the LZWDecode filter. This issue has been patched in version 6.4.0.

РелизСтатусПримечание
devel

needs-triage

esm-apps/noble

needs-triage

jammy

DNE

noble

needs-triage

plucky

ignored

end of life, was needs-triage
questing

needs-triage

upstream

not-affected

debian: Vulnerable code introduced later

Показывать по

EPSS

Процентиль: 22%
0.00073
Низкий

Связанные уязвимости

nvd
2 месяца назад

pypdf is a free and open-source pure-python PDF library. Prior to version 6.4.0, an attacker who uses this vulnerability can craft a PDF which leads to a memory usage of up to 1 GB per stream. This requires parsing the content stream of a page using the LZWDecode filter. This issue has been patched in version 6.4.0.

debian
2 месяца назад

pypdf is a free and open-source pure-python PDF library. Prior to vers ...

github
2 месяца назад

pypdf's LZWDecode streams be manipulated to exhaust RAM

EPSS

Процентиль: 22%
0.00073
Низкий