Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-18020

Опубликовано: 06 окт. 2018
Источник: debian
EPSS Низкий

Описание

In QPDF 8.2.1, in libqpdf/QPDFWriter.cc, QPDFWriter::unparseObject and QPDFWriter::unparseChild have recursive calls for a long time, which allows remote attackers to cause a denial of service via a crafted PDF file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
qpdffixed9.0.0-1package
qpdfno-dsastretchpackage
qpdfno-dsajessiepackage

Примечания

  • https://github.com/qpdf/qpdf/issues/243

  • https://github.com/qpdf/qpdf/commit/cf469d789024cdda41684f1ea48b41829b98c242

EPSS

Процентиль: 29%
0.00107
Низкий

Связанные уязвимости

CVSS3: 3.3
ubuntu
больше 7 лет назад

In QPDF 8.2.1, in libqpdf/QPDFWriter.cc, QPDFWriter::unparseObject and QPDFWriter::unparseChild have recursive calls for a long time, which allows remote attackers to cause a denial of service via a crafted PDF file.

CVSS3: 3.3
redhat
больше 7 лет назад

In QPDF 8.2.1, in libqpdf/QPDFWriter.cc, QPDFWriter::unparseObject and QPDFWriter::unparseChild have recursive calls for a long time, which allows remote attackers to cause a denial of service via a crafted PDF file.

CVSS3: 3.3
nvd
больше 7 лет назад

In QPDF 8.2.1, in libqpdf/QPDFWriter.cc, QPDFWriter::unparseObject and QPDFWriter::unparseChild have recursive calls for a long time, which allows remote attackers to cause a denial of service via a crafted PDF file.

CVSS3: 3.3
github
больше 3 лет назад

In QPDF 8.2.1, in libqpdf/QPDFWriter.cc, QPDFWriter::unparseObject and QPDFWriter::unparseChild have recursive calls for a long time, which allows remote attackers to cause a denial of service via a crafted PDF file.

CVSS3: 4.3
fstec
больше 7 лет назад

Уязвимость компонента libqpdf/QPDFWriter.cc утилиты командной строки для преобразования PDF документов QPDF, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 29%
0.00107
Низкий