VDB
Sign up
MEDIUM

GHSA-jxhh-4648-vpp3

FPDI allows Memory Exhaustion (OOM) in PDF Parser which leads to Denial of Service

Quick fix

GHSA-jxhh-4648-vpp3 — setasign/fpdi: upgrade to the fixed version with the command below.

composer require setasign/fpdi:^2.6.4

Details

### Impact This is a significant Denial of Service (DoS) vulnerability. Any application that uses FPDI to process user-supplied PDF files is at risk. An attacker can upload a small, malicious PDF file that will cause the server-side script to crash due to memory exhaustion. Repeated attacks can lead to sustained service unavailability.

### Patches Fixed as of version 2.6.4

### Workarounds No.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/setasign/fpdi
Introduced in: 0Fixed in: 2.6.4
Fixcomposer require setasign/fpdi:^2.6.4

References