GHSA-qv6h-rv94-w285: Pip/pypdf vulnerability
Impact
An attacker who uses this vulnerability can craft a PDF which leads to large memory consumption. This requires accessing the page labels of a document with large Roman numerals.
Patches
This has been fixed in pypdf==6.17.0.
Workarounds
If you cannot upgrade yet, consider applying the changes from PR #4047.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/pypdfto a version that resolves this vulnerability.Fixed in 6.17.0 - Upgrade
Upgrade
pypdfto a version that resolves this vulnerability.Fixed in 6.17.0 - Compensating control
If you cannot upgrade, apply the changes from PR #4047.
Event History
Frequently Asked Questions
What must an attacker do to trigger the excessive memory consumption?
The attacker must supply a crafted PDF and cause the application to access that document's page labels. The issue is triggered when those page labels contain large Roman numerals.
Which release fixes this issue?
The issue is fixed in pypdf 6.17.0.
What can be done if upgrading is not immediately possible?
Consider applying the changes from PR #4047 as a workaround.