PT-2018-19086 · Qpdf+3 · Qpdf+3

Pushdword

·

Publicado

2018-04-10

·

Atualizado

2024-06-24

·

CVE-2018-9918

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions QPDF versions prior to 8.0.3
Description The issue allows remote attackers to cause a denial of service (stack exhaustion) due to the mishandling of certain dictionary key cases. This is related to the QPDFObjectHandle and QPDF Dictionary classes, where nesting in direct objects is not restricted.
Recommendations For versions prior to 8.0.3, update to version 8.0.3 or later to resolve the issue.

Exploit

Correção

DoS

Uncontrolled Recursion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2018-1941
CVE-2018-9918
MGASA-2018-0232
SUSE-SU-2024:2173-1
SUSE-SU-2024_2173-1
USN-3638-1

Produtos afetados

Alt Linux
Qpdf
Suse
Ubuntu