An attacker who uses this vulnerability can craft a PDF which leads to unexpected long runtime. This quadratic runtime blocks the current process and can utilize a single core of the CPU by 100%. It does not affect memory usage.
https://github.com/py-pdf/pypdf/pull/808
Is there a way for users to fix or remediate the vulnerability without upgrading?
{ "nvd_published_at": "2023-06-30T19:15:09Z", "cwe_ids": [ "CWE-407" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2023-06-30T22:17:52Z" }