Описание
An issue was discovered in QPDF version 10.0.4, allows remote attackers to execute arbitrary code via crafted .pdf file to Pl_ASCII85Decoder::write parameter in libqpdf.
A flaw was found in the qpdf package. This issue may allow attackers to crash the system or execute arbitrary code via a crafted .pdf file to the Pl_ASCII85Decoder::write parameter in libqpdf.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 7 | qpdf | Out of support scope | ||
Red Hat Enterprise Linux 8 | qpdf | Will not fix | ||
Red Hat Enterprise Linux 9 | qpdf | Will not fix |
Показывать по
Дополнительная информация
Статус:
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
An issue was discovered in QPDF version 10.0.4, allows remote attackers to execute arbitrary code via crafted .pdf file to Pl_ASCII85Decoder::write parameter in libqpdf.
An issue was discovered in QPDF version 10.0.4, allows remote attackers to execute arbitrary code via crafted .pdf file to Pl_ASCII85Decoder::write parameter in libqpdf.
An issue was discovered in QPDF version 10.0.4, allows remote attacker ...
An issue was discovered in QPDF version 10.0.4, allows remote attackers to execute arbitrary code via crafted .pdf file to Pl_ASCII85Decoder::write parameter in libqpdf.
EPSS
5.3 Medium
CVSS3