PT-2017-4066 · Qpdf+3 · Qpdf+3
Agostino Sarubbo
·
Published
2017-05-23
·
Updated
2019-10-03
·
CVE-2017-9210
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
QPDF version 6.0.0
Description
The issue is related to an infinite recursion and stack consumption in the libqpdf.a component of QPDF, which can be triggered by a crafted PDF document. This can cause a denial of service. The problem is associated with unparse functions.
Recommendations
For QPDF version 6.0.0, consider avoiding the use of crafted PDF documents that may trigger the infinite recursion until a patch is available. As a temporary workaround, restrict the use of the libqpdf.a component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Infinite Loop
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Qpdf
Suse
Ubuntu