PT-2018-3927 · Qpdf+4 · Qpdf+4

·

CVE-2018-18020

·

Publicado

2018-10-06

·

Atualizado

2023-08-30

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions QPDF version 8.2.1
Description The issue is related to uncontrolled recursion in the libqpdf/QPDFWriter.cc component of the QPDF utility for converting PDF documents. This allows a remote attacker to cause a denial of service using a specially crafted PDF file. The estimated number of potentially affected devices worldwide is not available. There is no information about real-world incidents where this issue was exploited.
Recommendations For QPDF version 8.2.1, as a temporary workaround, consider restricting the use of the QPDFWriter::unparseObject and QPDFWriter::unparseChild functions until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Uncontrolled Recursion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2019-1083
BDU:2023-03810
CVE-2018-18020
DLA-3548-1
USN-5026-1
USN-5026-2

Produtos afetados

Alt Linux
Astra Linux
Linuxmint
Qpdf
Ubuntu