CVE-2023-36464
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Summary
CVE-2023-36464 is a vulnerability affecting the pypdf library, a popular open-source PDF library written in Python. In certain PDF files, an attacker can craft malicious content that triggers an infinite loop in the function `__parse_content_stream`. This issue, introduced in pull request #969 and resolved in #1828, can occur when extracting text from a manipulated PDF file. Users are strongly advised to upgrade to the latest version. For those unable to upgrade immediately, a temporary workaround involves modifying a single line in `pypdf/generic/_data_structures.py`.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Pypdf Project Pypdf