Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-18185

Опубликовано: 27 авг. 2017
Источник: redhat
CVSS3: 3.3
EPSS Низкий

Описание

An issue was discovered in QPDF before 7.0.0. There is a large heap-based out-of-bounds read in the Pl_Buffer::write function in Pl_Buffer.cc. It is caused by an integer overflow in the PNG filter.

An integer overflow flaw leading to heap-based out-of-bounds read was found in the way QPDF parsed PDF files. An attacker could potentially use this flaw to crash QPDF by tricking it into processing crafted QPDF files.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7qpdfWill not fix
Red Hat Enterprise Linux 8qpdfNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=1545283qpdf: large heap-based out-of-bounds read in the Pl_Buffer::write function in Pl_Buffer.cc

EPSS

Процентиль: 61%
0.0106
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 8 лет назад

An issue was discovered in QPDF before 7.0.0. There is a large heap-based out-of-bounds read in the Pl_Buffer::write function in Pl_Buffer.cc. It is caused by an integer overflow in the PNG filter.

CVSS3: 5.5
nvd
больше 8 лет назад

An issue was discovered in QPDF before 7.0.0. There is a large heap-based out-of-bounds read in the Pl_Buffer::write function in Pl_Buffer.cc. It is caused by an integer overflow in the PNG filter.

CVSS3: 5.5
debian
больше 8 лет назад

An issue was discovered in QPDF before 7.0.0. There is a large heap-ba ...

CVSS3: 5.5
github
больше 4 лет назад

An issue was discovered in QPDF before 7.0.0. There is a large heap-based out-of-bounds read in the Pl_Buffer::write function in Pl_Buffer.cc. It is caused by an integer overflow in the PNG filter.

EPSS

Процентиль: 61%
0.0106
Низкий

3.3 Low

CVSS3