Know every vulnerabilitybefore it knows you.
DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.
GHSA-jrmc-qg6p-94fp
No affected components available
Summary
Description
A PostScript-interpreter-driven Denial of Service (CWE-1325) vulnerability in veraPDF allows a remote attacker to exhaust validator memory or CPU by submitting a PDF whose Type 0 font /Encoding (or any /ToUnicode) is a CMap stream containing attacker-supplied PostScript. veraPDF reuses its CMap parser as a general PostScript interpreter and exposes the unguarded array N allocation operator and the for control operator with no zero-increment guard. This affects all current versions of veraPDF-parser.
Details
The vulnerability resides in veraPDF-parser. CMap streams referenced as a Type 0 font's /Encoding (or any font's /ToUnicode) are parsed by CMapParser (veraPDF-parser/src/main/java/org/verapdf/pd/font/cmap/CMapParser.java), which extends PSParser. Tokens that are not the small CMap-specific keyword set (begincodespacerange, bfchar, cidchar, ...) fall through to PSObject.execute (veraPDF-parser/src/main/java/org/verapdf/parser/postscript/PSObject.java), which dispatches generic PostScript operators implemented in PSOperator (veraPDF-parser/src/main/java/org/verapdf/parser/postscript/PSOperator.java).
Two operators in that interpreter take their bound from the PDF and apply no validation:
arrayat PSOperator.java:536-547 pops the top number from the operand stack and immediately callsCOSArray.construct(arraySize), then loopsarraySizetimes appendingCOSObject.getEmpty().COSArray.construct(int)callsnew ArrayList<>(arraySize)(COSArray.java:102), so the underlyingObject[]is allocated up-front. Passing2147483647(Integer.MAX_VALUE) requests a 16 GB backing array on a 64-bit JVM.forat PSOperator.java:571-592 readsinitial,increment, andlimitfrom the stack and loopsfor (long i = initial; i <= limit; i += increment). Becauseincrementis unchecked,0 0 1 { } forproduces an infinite-CPU spin (and progressively a heap exhaustion as each iteration pushesionto the operand stack).
CMapFactory.getCMap only catches IOException and PostScriptException; it does not catch OutOfMemoryError or wall-clock budget, so the failure propagates out of font model construction and aborts the validation worker.
A single payload byte sequence, the unframed PostScript 2147483647 array, is sufficient. No begincmap/endcmap framing is required because the operator runs before the parser ever reaches the CMap structure.
Impact
This impacts all current releases of the veraPDF-parser. Successful exploitation requires only that the target validate an attacker-supplied PDF; a single Type 0 font with a malicious /Encoding (or any /ToUnicode) stream is sufficient.
Proposed Patch
Cap array allocation and forbid zero increments in for.
As a defensive measure, also wrap CMapFactory.getCMap to enforce a wall-clock and operand-stack-size budget on CMap parsing, and audit the remaining unbounded operators (copy, roll, dict) for similar primitives.
The vulnerability can be exploited over the network without needing physical access. It is easy for an attacker to exploit this vulnerability. An attacker does not need any special privileges or access rights. No user interaction is needed for the attacker to exploit this vulnerability.
Limited exploitation activity has been observed. Close monitoring and planned remediation are recommended.
The exploit probability is very low. The vulnerability is unlikely to be exploited in the next 30 days.
We did not find any exploit available. Neither in GitHub repositories nor in the Exploit-Database.
Browse More
Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.
Checkout DevGuard