PT-2017-4066 · Qpdf+3 · Qpdf+3

Agostino Sarubbo

·

Published

2017-05-23

·

Updated

2019-10-03

·

CVE-2017-9210

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions QPDF version 6.0.0
Description The issue is related to an infinite recursion and stack consumption in the libqpdf.a component of QPDF, which can be triggered by a crafted PDF document. This can cause a denial of service. The problem is associated with unparse functions.
Recommendations For QPDF version 6.0.0, consider avoiding the use of crafted PDF documents that may trigger the infinite recursion until a patch is available. As a temporary workaround, restrict the use of the libqpdf.a component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Infinite Loop

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2017-2228
BDU:2021-01402
CVE-2017-9210
MGASA-2017-0237
MGASA-2018-0145
SUSE-SU-2018:3066-1
SUSE-SU-2018:3066-2
USN-3638-1

Affected Products

Alt Linux
Qpdf
Suse
Ubuntu