PT-2017-4066 · Qpdf+3 · Qpdf+3

Agostino Sarubbo

·

Publicado

2017-05-23

·

Atualizado

2019-10-03

·

CVE-2017-9210

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions QPDF version 6.0.0
Description The issue is related to an infinite recursion and stack consumption in the libqpdf.a component of QPDF, which can be triggered by a crafted PDF document. This can cause a denial of service. The problem is associated with unparse functions.
Recommendations For QPDF version 6.0.0, consider avoiding the use of crafted PDF documents that may trigger the infinite recursion until a patch is available. As a temporary workaround, restrict the use of the libqpdf.a component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Infinite Loop

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-2228
BDU:2021-01402
CVE-2017-9210
MGASA-2017-0237
MGASA-2018-0145
SUSE-SU-2018:3066-1
SUSE-SU-2018:3066-2
USN-3638-1

Produtos afetados

Alt Linux
Qpdf
Suse
Ubuntu