PT-2018-6716 · Qpdf+2 · Qpdf+2

Hannob

·

Publicado

2017-09-18

·

Atualizado

2018-05-08

·

CVE-2017-18185

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: QPDF versions prior to 7.0.0
Description: An issue was discovered in QPDF, where a large heap-based out-of-bounds read occurs in the Pl Buffer::write function. This is caused by an integer overflow in the PNG filter.
Recommendations: For versions prior to 7.0.0, update to version 7.0.0 or later to resolve the issue.

Correção

Out of bounds Read

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2017-2228
CVE-2017-18185
USN-3638-1

Produtos afetados

Alt Linux
Qpdf
Ubuntu