Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-9918

Опубликовано: 10 апр. 2018
Источник: redhat
CVSS3: 3.3
EPSS Низкий

Описание

libqpdf.a in QPDF through 8.0.2 mishandles certain "expected dictionary key but found non-name object" cases, allowing remote attackers to cause a denial of service (stack exhaustion), related to the QPDFObjectHandle and QPDF_Dictionary classes, because nesting in direct objects is not restricted.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7qpdfWill not fix
Red Hat Enterprise Linux 8qpdfNot affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1566756qpdf: stack exhaustion in QPDFObjectHandle and QPDF_Dictionary classes in libqpdf.a

EPSS

Процентиль: 75%
0.00857
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
почти 8 лет назад

libqpdf.a in QPDF through 8.0.2 mishandles certain "expected dictionary key but found non-name object" cases, allowing remote attackers to cause a denial of service (stack exhaustion), related to the QPDFObjectHandle and QPDF_Dictionary classes, because nesting in direct objects is not restricted.

CVSS3: 7.8
nvd
почти 8 лет назад

libqpdf.a in QPDF through 8.0.2 mishandles certain "expected dictionary key but found non-name object" cases, allowing remote attackers to cause a denial of service (stack exhaustion), related to the QPDFObjectHandle and QPDF_Dictionary classes, because nesting in direct objects is not restricted.

CVSS3: 7.8
debian
почти 8 лет назад

libqpdf.a in QPDF through 8.0.2 mishandles certain "expected dictionar ...

suse-cvrf
больше 1 года назад

Security update for qpdf

CVSS3: 7.8
github
больше 3 лет назад

libqpdf.a in QPDF through 8.0.2 mishandles certain "expected dictionary key but found non-name object" cases, allowing remote attackers to cause a denial of service (stack exhaustion), related to the QPDFObjectHandle and QPDF_Dictionary classes, because nesting in direct objects is not restricted.

EPSS

Процентиль: 75%
0.00857
Низкий

3.3 Low

CVSS3