Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-25786

Опубликовано: 11 авг. 2023
Источник: debian

Описание

An issue was discovered in QPDF version 10.0.4, allows remote attackers to execute arbitrary code via crafted .pdf file to Pl_ASCII85Decoder::write parameter in libqpdf.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
qpdffixed10.1.0-1package

Примечания

  • https://github.com/qpdf/qpdf/issues/492

  • https://github.com/qpdf/qpdf/commit/dc92574c10f3e2516ec6445b88c5d584f40df4e5 (release-qpdf-10.1.0)

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 2 лет назад

An issue was discovered in QPDF version 10.0.4, allows remote attackers to execute arbitrary code via crafted .pdf file to Pl_ASCII85Decoder::write parameter in libqpdf.

CVSS3: 5.3
redhat
больше 2 лет назад

An issue was discovered in QPDF version 10.0.4, allows remote attackers to execute arbitrary code via crafted .pdf file to Pl_ASCII85Decoder::write parameter in libqpdf.

CVSS3: 5.3
nvd
больше 2 лет назад

An issue was discovered in QPDF version 10.0.4, allows remote attackers to execute arbitrary code via crafted .pdf file to Pl_ASCII85Decoder::write parameter in libqpdf.

CVSS3: 5.3
redos
9 месяцев назад

Уязвимость qpdf

CVSS3: 8.8
github
больше 2 лет назад

An issue was discovered in QPDF version 10.0.4, allows remote attackers to execute arbitrary code via crafted .pdf file to Pl_ASCII85Decoder::write parameter in libqpdf.