PT-2018-3927 · Qpdf+4 · Qpdf+4

Krace

·

Published

2018-10-06

·

Updated

2023-08-30

·

CVE-2018-18020

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions QPDF version 8.2.1
Description The issue is related to uncontrolled recursion in the libqpdf/QPDFWriter.cc component of the QPDF utility for converting PDF documents. This allows a remote attacker to cause a denial of service using a specially crafted PDF file. The estimated number of potentially affected devices worldwide is not available. There is no information about real-world incidents where this issue was exploited.
Recommendations For QPDF version 8.2.1, as a temporary workaround, consider restricting the use of the QPDFWriter::unparseObject and QPDFWriter::unparseChild functions until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Uncontrolled Recursion

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1083
BDU:2023-03810
CVE-2018-18020
DLA-3548-1
USN-5026-1
USN-5026-2

Affected Products

Alt Linux
Astra Linux
Linuxmint
Qpdf
Ubuntu