PT-2020-6937 · Pypi+3 · Pypdf+3

Martin Thoma

·

Published

2020-11-13

·

Updated

2023-09-11

·

CVE-2023-36810

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions pypdf versions prior to 1.27.9
Description The issue is related to algorithmic complexity in the pypdf library, which can be exploited by an attacker to craft a PDF that leads to unexpected long runtime, blocking the current process and utilizing a single core of the CPU by 100%. This does not affect memory usage.
Recommendations For versions prior to 1.27.9, upgrade to version 1.27.9 or later to resolve the issue. As a temporary workaround, consider restricting the use of the pypdf library until a patch is applied.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BDU:2023-07658
CVE-2023-36810
DLA-3497-1
GHSA-JRM6-H9CQ-8GQW
MGASA-2023-0254
USN-6280-1

Affected Products

Astra Linux
Linuxmint
Ubuntu
Pypdf