HIGH8.8
GHSA-wgrm-67xf-hhpq
PDF.js vulnerable to arbitrary JavaScript execution upon opening a malicious PDF
Quick fix
GHSA-wgrm-67xf-hhpq — pdfjs-dist: upgrade to the fixed version with the command below.
npm install pdfjs-dist@4.2.67Details
### Impact If pdf.js is used to load a malicious PDF, and PDF.js is configured with `isEvalSupported` set to `true` (which is the default value), unrestricted attacker-controlled JavaScript will be executed in the context of the hosting domain.
### Patches The patch removes the use of `eval`: https://github.com/mozilla/pdf.js/pull/18015
### Workarounds Set the option `isEvalSupported` to `false`.
### References https://bugzilla.mozilla.org/show_bug.cgi?id=1893645
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/mozilla/pdf.js/security/advisories/GHSA-wgrm-67xf-hhpq[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2024-4367[ADVISORY]
- https://github.com/gogs/gogs/issues/7928[WEB]
- https://github.com/mozilla/pdf.js/pull/18015[WEB]
- https://github.com/mozilla/pdf.js/commit/85e64b5c16c9aaef738f421733c12911a441cec6[WEB]
- https://bugzilla.mozilla.org/show_bug.cgi?id=1893645[WEB]
- https://cert-portal.siemens.com/productcert/html/ssa-827383.html[WEB]
- https://codeanlabs.com/blog/research/cve-2024-4367-arbitrary-js-execution-in-pdf-js[WEB]
- https://github.com/mozilla/pdf.js[PACKAGE]
- https://github.com/mozilla/pdf.js/releases/tag/v4.2.67[WEB]
- https://lists.debian.org/debian-lts-announce/2024/05/msg00010.html[WEB]
- https://lists.debian.org/debian-lts-announce/2024/05/msg00012.html[WEB]
- https://www.exploit-db.com/exploits/52273[WEB]
- https://www.mozilla.org/security/advisories/mfsa2024-21[WEB]
- https://www.mozilla.org/security/advisories/mfsa2024-22[WEB]
- https://www.mozilla.org/security/advisories/mfsa2024-23[WEB]
- http://seclists.org/fulldisclosure/2024/Aug/30[WEB]