PT-2018-19086 · Qpdf+3 · Qpdf+3

Pushdword

·

Published

2018-04-10

·

Updated

2024-06-24

·

CVE-2018-9918

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions QPDF versions prior to 8.0.3
Description The issue allows remote attackers to cause a denial of service (stack exhaustion) due to the mishandling of certain dictionary key cases. This is related to the QPDFObjectHandle and QPDF Dictionary classes, where nesting in direct objects is not restricted.
Recommendations For versions prior to 8.0.3, update to version 8.0.3 or later to resolve the issue.

Exploit

Fix

DoS

Uncontrolled Recursion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2018-1941
CVE-2018-9918
MGASA-2018-0232
SUSE-SU-2024:2173-1
SUSE-SU-2024_2173-1
USN-3638-1

Affected Products

Alt Linux
Qpdf
Suse
Ubuntu