PT-2023-12077 · Qpdf+1 · Qpdf+1

Bin2415

·

Published

2021-07-29

·

Updated

2025-04-03

·

CVE-2021-25786

CVSS v3.1

5.3

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions QPDF version 10.0.4
Description An issue was discovered in QPDF, allowing remote attackers to execute arbitrary code via a crafted .pdf file. The Pl ASCII85Decoder::write parameter in libqpdf is vulnerable to this attack.
Recommendations For QPDF version 10.0.4, consider disabling the Pl ASCII85Decoder::write function until a patch is available to prevent exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-04290
CVE-2021-25786
DLA-3548-1
OESA-2023-1542
USN-5026-1
USN-5026-2

Affected Products

Qpdf
Red Os