Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-66019

Опубликовано: 26 нояб. 2025
Источник: ubuntu
Приоритет: medium
EPSS Низкий

Описание

pypdf is a free and open-source pure-python PDF library. Prior to version 6.4.0, an attacker who uses this vulnerability can craft a PDF which leads to a memory usage of up to 1 GB per stream. This requires parsing the content stream of a page using the LZWDecode filter. This issue has been patched in version 6.4.0.

РелизСтатусПримечание
devel

needs-triage

esm-apps/noble

needs-triage

esm-apps/resolute

needs-triage

jammy

DNE

noble

needs-triage

plucky

ignored

end of life, was needs-triage
questing

ignored

end of life, was needs-triage
resolute

needs-triage

upstream

not-affected

debian: Vulnerable code introduced later

Показывать по

EPSS

Процентиль: 28%
0.00353
Низкий

Связанные уязвимости

CVSS3: 5.3
redhat
8 месяцев назад

pypdf is a free and open-source pure-python PDF library. Prior to version 6.4.0, an attacker who uses this vulnerability can craft a PDF which leads to a memory usage of up to 1 GB per stream. This requires parsing the content stream of a page using the LZWDecode filter. This issue has been patched in version 6.4.0.

nvd
8 месяцев назад

pypdf is a free and open-source pure-python PDF library. Prior to version 6.4.0, an attacker who uses this vulnerability can craft a PDF which leads to a memory usage of up to 1 GB per stream. This requires parsing the content stream of a page using the LZWDecode filter. This issue has been patched in version 6.4.0.

debian
8 месяцев назад

pypdf is a free and open-source pure-python PDF library. Prior to vers ...

github
8 месяцев назад

pypdf's LZWDecode streams be manipulated to exhaust RAM

CVSS3: 7.5
fstec
10 месяцев назад

Уязвимость библиотеки Python для работы с PDF файлами PyPDF, связанная с некорректной обработкой сильно сжатых входных данных, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 28%
0.00353
Низкий
Уязвимость CVE-2025-66019