PT-2023-21713 · Pdfio+1 · Pdfio+1

Cyberitech

·

Published

2023-03-20

·

Updated

2023-03-24

·

CVE-2023-28428

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions PDFio versions 1.1.0 and prior
Description A denial of service issue exists in the pdfio parser, where crafted PDF files can cause the program to run at 100% utilization and never terminate.
Recommendations For PDFio versions 1.1.0 and prior, update to version 1.1.1 to resolve the issue.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

CVE-2023-28428
GHSA-68X8-9PHF-J7JF

Affected Products

Debian
Pdfio