VDB
Sign up
HIGH8.8

GHSA-7jg2-jgv3-fmr4

Malicious PDF can inject JavaScript into PDF Viewer

Quick fix

GHSA-7jg2-jgv3-fmr4 — pdfjs-dist: upgrade to the fixed version with the command below.

npm install pdfjs-dist@2.0.550

Details

The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious JavaScript to be injected through a crafted PDF file. This JavaScript can then be run with the permissions of the PDF viewer by its worker. This vulnerability affects Firefox ESR < 52.8, Firefox < 60 and PDF.js < 2.0.550.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/pdfjs-dist
Introduced in: 2.0.0Fixed in: 2.0.550
Fixnpm install pdfjs-dist@2.0.550
npm/pdfjs-dist
Introduced in: 0Fixed in: 1.10.100
Fixnpm install pdfjs-dist@1.10.100

References