Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-36978

Опубликовано: 20 июл. 2021
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.3
CVSS3: 5.5

Описание

QPDF 9.x through 9.1.1 and 10.x through 10.0.4 has a heap-based buffer overflow in Pl_ASCII85Decoder::write (called from Pl_AES_PDF::flush and Pl_AES_PDF::finish) when a certain downstream write fails.

РелизСтатусПримечание
bionic

released

8.0.2-3ubuntu0.1
devel

not-affected

esm-infra-legacy/trusty

DNE

esm-infra/bionic

released

8.0.2-3ubuntu0.1
esm-infra/focal

released

9.1.1-1ubuntu0.1
esm-infra/xenial

released

8.0.2-3~16.04.1+esm1
focal

released

9.1.1-1ubuntu0.1
hirsute

not-affected

10.3.1-1
impish

not-affected

jammy

not-affected

Показывать по

EPSS

Процентиль: 24%
0.00079
Низкий

4.3 Medium

CVSS2

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.8
redhat
больше 4 лет назад

QPDF 9.x through 9.1.1 and 10.x through 10.0.4 has a heap-based buffer overflow in Pl_ASCII85Decoder::write (called from Pl_AES_PDF::flush and Pl_AES_PDF::finish) when a certain downstream write fails.

CVSS3: 5.5
nvd
около 4 лет назад

QPDF 9.x through 9.1.1 and 10.x through 10.0.4 has a heap-based buffer overflow in Pl_ASCII85Decoder::write (called from Pl_AES_PDF::flush and Pl_AES_PDF::finish) when a certain downstream write fails.

CVSS3: 5.5
debian
около 4 лет назад

QPDF 9.x through 9.1.1 and 10.x through 10.0.4 has a heap-based buffer ...

suse-cvrf
почти 3 года назад

Security update for qpdf

CVSS3: 5.5
redos
8 дней назад

Уязвимость qpdf

EPSS

Процентиль: 24%
0.00079
Низкий

4.3 Medium

CVSS2

5.5 Medium

CVSS3