CVE-2023-24808 is a denial-of-service vulnerability affecting PDFio, a C library for reading and writing PDF files, in versions prior to 1.1.0. A specially crafted PDF file can cause the pdfio parser to consume 100% CPU and never terminate, impacting any application or server relying on this library. Rated Medium (CVSS 6.5), it requires user interaction (UI:R) to open the malicious file, but the attack complexity is low (AC:L) and results in high availability impact (A:H). There is no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.1.0CPE matchmatch criteria | cpe:2.3:a:pdfio_project:pdfio:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.