VDB
Sign up
MEDIUM

GHSA-2mgw-7q6p-8grg

FPDI: Memory Exhaustion and Endless Loop in FPDI leads to Denial of Service

Quick fix

GHSA-2mgw-7q6p-8grg — setasign/fpdi: upgrade to the fixed version with the command below.

composer require setasign/fpdi:^2.6.7

Details

### Impact This is a significant Denial of Service (DoS) vulnerability. Any application that uses FPDI to process user-supplied PDF files is at risk. An attacker can upload a small, malicious PDF file that will cause the server-side script to crash due to memory exhaustion or a script time-out. Repeated attacks can lead to sustained service unavailability.

### Patches Fixed as of version 2.6.7

### Workarounds No.

### References No.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/setasign/fpdi
Introduced in: 0Fixed in: 2.6.7
Fixcomposer require setasign/fpdi:^2.6.7

References