Skip to content

Security Vulnerability #18168

Answered by Snuffleupagus
k-yle asked this question in Q&A
Discussion options

You must be logged in to vote

Will the fix for CVE-2024-4367 be backported to v3? (#18015)

No, that's unfortunately not planned. Please note that there's a bunch of manual work involved in creating releases, and the 3.x branch has been completely unsupported for quite some time.
Also, as outlined in the advisory, it's trivial to workaround the problem in older PDF.js versions simply by setting isEvalSupported: false in the getDocument-call.

Separately, it seems like https://github.com/mozilla/pdfjs-dist is no longer being updated.

Yes, that's unfortunately a known problem but we're not sure how/why it broke. The intention is to fix this, but it depends on issue #11851 being implemented.
However, please note that h…

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by Snuffleupagus
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants