PT-2024-38774 · Progress · Telerik Document Processing Libraries
Published
2024-11-13
·
Updated
2024-11-18
·
CVE-2024-8049
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Progress Telerik Document Processing Libraries versions prior to 2024 Q4 (2024.4.1106)
Description:
The issue arises when importing a document with unsupported features, leading to excessive processing and excessive use of computing resources. This results in the application process becoming unavailable due to resource exhaustion.
Recommendations:
For versions prior to 2024 Q4 (2024.4.1106), update to version 2024.4.1106 or later to resolve the issue. As a temporary workaround, consider restricting the import of documents with unsupported features to minimize the risk of excessive processing and resource exhaustion.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Telerik Document Processing Libraries