security advisorydebianruntime issue
Quadratic runtime with malformed PDFs missing xref marker has been fixed in PyPDF2, a pure Python PDF library. For Debian 10 buster, this problem has been fixed in version . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3497-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Adrian Bunk July 14, 2023 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : pypdf2 Version : 1.26.0-2+deb10u2 CVE ID : CVE-2023-36810 Quadratic runtime with malformed PDFs missing xref marker has been fixed in PyPDF2, a pure Python PDF library. For Debian 10 buster, this problem has been fixed in version 1.26.0-2+deb10u2. We recommend that you upgrade your pypdf2 packages. For the detailed security status of pypdf2 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/pypdf2 Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian long-term support patches resolve exponential time complexity bug in PyPDF2 related to corrupt PDF files. Users are advised to upgrade for improved security.. Debian 10, security advisory, PyPDF2 update, runtime fix. . LinuxSecurity.com Team
Jul 14, 2023
Debian LTS