First published: Mon Mar 20 2023(Updated: )
PDFio is a C library for reading and writing PDF files. In versions 1.1.0 and prior, a denial of service vulnerability exists in the pdfio parser. Crafted pdf files can cause the program to run at 100% utilization and never terminate. This is different from CVE-2023-24808. A patch for this issue is available in version 1.1.1.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Pdfio | <1.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-28428 is a denial of service vulnerability in the pdfio parser of PDFio library.
The severity of CVE-2023-28428 is medium with a severity value of 3.3.
CVE-2023-28428 affects PDFio library versions 1.1.0 and prior, allowing crafted PDF files to cause the program to run at 100% utilization and never terminate.
Yes, CVE-2023-28428 is a different vulnerability from CVE-2023-24808.
To fix CVE-2023-28428, update PDFio library to version 1.1.1 or later.