An attacker who uses this vulnerability can craft a PDF which leads to unexpected long runtime. This quadratic runtime blocks the current process and can utilize a single core of the CPU by 100%. It does not affect memory usage.
https://github.com/py-pdf/pypdf/pull/808
Is there a way for users to fix or remediate the vulnerability without upgrading?
{ "github_reviewed_at": "2023-06-30T22:17:52Z", "cwe_ids": [ "CWE-407" ], "nvd_published_at": "2023-06-30T19:15:09Z", "severity": "MODERATE", "github_reviewed": true }