Vulnerability Details CVE-2023-28428
PDFio is a C library for reading and writing PDF files. In versions 1.1.0 and prior, a denial of service vulnerability exists in the pdfio parser. Crafted pdf files can cause the program to run at 100% utilization and never terminate. This is different from CVE-2023-24808. A patch for this issue is available in version 1.1.1.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 11.5%
CVSS Severity
CVSS v3 Score 6.2
Products affected by CVE-2023-28428
-
cpe:2.3:a:pdfio_project:pdfio:1.0
-
cpe:2.3:a:pdfio_project:pdfio:1.0.0
-
cpe:2.3:a:pdfio_project:pdfio:1.0.1
-
cpe:2.3:a:pdfio_project:pdfio:1.1.0