{"id":"GHSA-xcjx-m2pj-8g79","summary":"Manipulated inline images can cause Infinite Loop in PyPDF2","details":"### Impact\n\nAn attacker who uses this vulnerability can craft a PDF which leads to an infinite loop if the PyPDF2 user wrote the following code:\n\n```python\nfrom PyPDF2 import PdfFileReader, PdfFileWriter\nfrom PyPDF2.pdf import ContentStream\n\nreader = PdfFileReader(\"malicious.pdf\", strict=False)\nfor page in reader.pages:\n    ContentStream(page.getContents(), reader)\n```\n\n### Patches\n\n[`PyPDF2==1.27.5`](https://pypi.org/project/PyPDF2) and later are patched.\n\nCredits to [Sebastian Krause](https://github.com/sekrause) for finding ([issue](https://github.com/py-pdf/PyPDF2/issues/329)) and fixing ([PR](https://github.com/py-pdf/PyPDF2/pull/740)) it.\n","aliases":["CVE-2022-24859","PYSEC-2022-194"],"modified":"2024-10-14T18:30:12.021140Z","published":"2022-04-22T20:54:41Z","database_specific":{"cwe_ids":["CWE-835"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2022-04-22T20:54:41Z","nvd_published_at":"2022-04-18T19:15:00Z"},"references":[{"type":"WEB","url":"https://github.com/py-pdf/PyPDF2/security/advisories/GHSA-xcjx-m2pj-8g79"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-24859"},{"type":"WEB","url":"https://github.com/py-pdf/PyPDF2/issues/329"},{"type":"WEB","url":"https://github.com/py-pdf/PyPDF2/pull/740"},{"type":"PACKAGE","url":"https://github.com/py-pdf/PyPDF2"},{"type":"WEB","url":"https://github.com/py-pdf/PyPDF2/releases/tag/1.27.5"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/pypdf2/PYSEC-2022-194.yaml"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2022/06/msg00001.html"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2023/06/msg00013.html"}],"affected":[{"package":{"name":"pypdf2","ecosystem":"PyPI","purl":"pkg:pypi/pypdf2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.27.5"}]}],"versions":["1.15","1.16","1.17","1.18","1.19","1.20","1.21","1.22","1.23","1.24","1.25","1.25.1","1.26.0","1.27.0","1.27.1","1.27.2","1.27.3","1.27.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-xcjx-m2pj-8g79/GHSA-xcjx-m2pj-8g79.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}