Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-36978

Опубликовано: 04 янв. 2021
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

QPDF 9.x through 9.1.1 and 10.x through 10.0.4 has a heap-based buffer overflow in Pl_ASCII85Decoder::write (called from Pl_AES_PDF::flush and Pl_AES_PDF::finish) when a certain downstream write fails.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7qpdfOut of support scope
Red Hat Enterprise Linux 8qpdfWill not fix
Red Hat Enterprise Linux 9qpdfNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=1984609qpdf: heap-based buffer overflow in Pl_ASCII85Decoder::write() when a certain downstream write fails

EPSS

Процентиль: 24%
0.00079
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 4 лет назад

QPDF 9.x through 9.1.1 and 10.x through 10.0.4 has a heap-based buffer overflow in Pl_ASCII85Decoder::write (called from Pl_AES_PDF::flush and Pl_AES_PDF::finish) when a certain downstream write fails.

CVSS3: 5.5
nvd
больше 4 лет назад

QPDF 9.x through 9.1.1 and 10.x through 10.0.4 has a heap-based buffer overflow in Pl_ASCII85Decoder::write (called from Pl_AES_PDF::flush and Pl_AES_PDF::finish) when a certain downstream write fails.

CVSS3: 5.5
debian
больше 4 лет назад

QPDF 9.x through 9.1.1 and 10.x through 10.0.4 has a heap-based buffer ...

suse-cvrf
больше 3 лет назад

Security update for qpdf

CVSS3: 5.5
github
больше 3 лет назад

QPDF 9.x through 9.1.1 and 10.x through 10.0.4 has a heap-based buffer overflow in Pl_ASCII85Decoder::write (called from Pl_AES_PDF::flush and Pl_AES_PDF::finish) when a certain downstream write fails.

EPSS

Процентиль: 24%
0.00079
Низкий

7.8 High

CVSS3