Description
pypdf is a free and open-source pure-python PDF library. Prior to 6.13.3, a maliciously crafted PDF can cause DoS. An attacker who uses this vulnerability can craft a PDF which leads to large memory usage, as MAX_DECLARED_STREAM_LENGTH is sometimes ignored. This requires parsing a content stream without a /Length value. This issue has been fixed in version 6.13.3.
Mitigation
Minimal update. May introduce new vulnerabilities or breaking changes.
|
 debian 12 | | =3.17.4-1 || =3.4.1-1 || =3.4.1-1+deb12u1 || =4.0.0-1 || =4.0.0-1~exp1 || =4.0.1-1 || =4.0.2-1 || =4.1.0-1 || =4.2.0-1 || =4.3.1-1 || =5.4.0-1 || =6.9.0-1 || =6.9.2-1 || =6.9.2-2 | - |
 debian 13 | | =5.4.0-1 || =6.9.0-1 || =6.9.2-1 || =6.9.2-2 | - |
 debian 14 | | =5.4.0-1 || =6.9.0-1 || =6.9.2-1 || =6.9.2-2 | - |
 debian 12 | | =2.12.1-3 || =2.12.1-3+deb12u1 || =2.12.1-4 | - |
 pypi | | =1.0 || =1.1 || =1.10 || =1.11 || =1.12 || =1.13 || =1.2 || =1.3 || =1.4 || =1.5 || =1.6 || =1.7 || =1.8 || =1.9 || =3.1.0 || =3.10.0 || =3.11.0 || =3.11.1 || =3.12.0 || =3.12.1 || =3.12.2 || =3.13.0 || =3.14.0 || =3.15.0 || =3.15.1 || =3.15.2 || =3.15.3 || =3.15.4 || =3.15.5 || =3.16.0 || =3.16.1 || =3.16.2 || =3.16.3 || =3.16.4 || =3.17.0 || =3.17.1 || =3.17.2 || =3.17.3 || =3.17.4 || =3.2.0 || =3.2.1 || =3.3.0 || =3.4.0 || =3.4.1 || =3.5.0 || =3.5.1 || =3.5.2 || =3.6.0 || =3.7.0 || =3.7.1 || =3.8.0 || =3.8.1 || =3.9.0 || =3.9.1 || =4.0.0 || =4.0.1 || =4.0.2 || =4.1.0 || =4.2.0 || =4.3.0 || =4.3.1 || =5.0.0 || =5.0.1 || =5.1.0 || =5.2.0 || =5.3.0 || =5.3.1 || =5.4.0 || =5.5.0 || =5.6.0 || =5.6.1 || =5.7.0 || =5.8.0 || =5.9.0 || =6.0.0 || =6.1.0 || =6.1.1 || =6.1.2 || =6.1.3 || =6.10.0 || =6.10.1 || =6.10.2 || =6.11.0 || =6.12.0 || =6.12.1 || =6.12.2 || =6.13.0 || =6.13.1 || =6.13.2 || =6.2.0 || =6.3.0 || =6.4.0 || =6.4.1 || =6.4.2 || =6.5.0 || =6.6.0 || =6.6.1 || =6.6.2 || =6.7.0 || =6.7.1 || =6.7.2 || =6.7.3 || =6.7.4 || =6.7.5 || =6.8.0 || =6.9.0 || =6.9.1 || =6.9.2 || >=0 <6.13.3 | 6.13.3 |