PT-2023-12077 · Qpdf+1 · Qpdf+1

Bin2415

·

Publicado

2021-07-29

·

Atualizado

2025-04-03

·

CVE-2021-25786

CVSS v3.1

5.3

Média

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions QPDF version 10.0.4
Description An issue was discovered in QPDF, allowing remote attackers to execute arbitrary code via a crafted .pdf file. The Pl ASCII85Decoder::write parameter in libqpdf is vulnerable to this attack.
Recommendations For QPDF version 10.0.4, consider disabling the Pl ASCII85Decoder::write function until a patch is available to prevent exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-04290
CVE-2021-25786
DLA-3548-1
OESA-2023-1542
USN-5026-1
USN-5026-2

Produtos afetados

Qpdf
Red Os