An attacker who uses this vulnerability can craft a PDF which leads to unexpected long runtime. This quadratic runtime blocks the current process and can utilize a single core of the CPU by 100%. It does not affect memory usage.
https://github.com/py-pdf/pypdf/pull/808
Is there a way for users to fix or remediate the vulnerability without upgrading?
{
"github_reviewed_at": "2023-06-30T22:17:52Z",
"github_reviewed": true,
"cwe_ids": [
"CWE-407"
],
"nvd_published_at": "2023-06-30T19:15:09Z",
"severity": "MODERATE"
}