CVE-2023-36464

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Jun 27, 2023
Updated: Jul 6, 2023
CWE ID 835

Summary

CVE-2023-36464 is a vulnerability affecting the pypdf library, a popular open-source PDF library written in Python. In certain PDF files, an attacker can craft malicious content that triggers an infinite loop in the function `__parse_content_stream`. This issue, introduced in pull request #969 and resolved in #1828, can occur when extracting text from a manipulated PDF file. Users are strongly advised to upgrade to the latest version. For those unable to upgrade immediately, a temporary workaround involves modifying a single line in `pypdf/generic/_data_structures.py`.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share