It was discovered that python-pypdf2 contained a vulnerability whereby an attacker can craft a PDF which leads to unexpected long runtime. (CVE-2023-36810). References: . MGASA-2023-0254 - Updated python-pypdf2 packages fix security vulnerability Publication date: 11 Sep 2023 URL: https://advisories.mageia.org/MGASA-2023-0254.html Type: security Affected Mageia releases: 8, 9 CVE: CVE-2023-36810 It was discovered that python-pypdf2 contained a vulnerability whereby an attacker can craft a PDF which leads to unexpected long runtime. (CVE-2023-36810). References: - https://bugs.mageia.org/show_bug.cgi?id=32115 - https://lists.debian.org/debian-lts-announce/2023/07/msg00019.html - https://www.cve.org/CVERecord?id=CVE-2023-36810 SRPMS: - 9/core/python-pypdf2-1.27.9-1.mga9 - 8/core/python-pypdf2-1.27.9-1.mga8 . Recent enhancements to the python-pypdf2 libraries address a runtime vulnerability impacting Mageia versions 8 and 9 following its identification.. python-pypdf2 runtime attack, Mageia security update, MGASA security advisory. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.