The tokenizer in QPDF 6.0.0 and 7.0.b1 is recursive for arrays and dictionaries, which allows remote attackers to cause a denial of service (stack consumption and segmentation fault) or possibly have unspecified other impact via a PDF document with a deep data structure, as demonstrated by a crash in QPDFObjectHandle::parseInternal in libqpdf/QPDFObjectHandle.cc.
CVSS Details
- CVSS 3.0 Base Score: 7.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade qpdf | Aug 22, 2024 | Aug 27, 2017 |
| Debian | — | Upgrade qpdf | Jul 30, 2024 | Aug 27, 2017 |
| Huawei Euleros 2_0_sp3 | — | Upgrade qpdf-libs | Apr 30, 2021 | Aug 27, 2017 |
| Huawei Euleros 2_0_sp5 | — | Upgrade qpdf-libs | Mar 24, 2021 | Aug 27, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Aug 22, 2017 |
| Suse | — | Upgrade libqpdf21Upgrade cups-filters-ghostscriptUpgrade qpdf-develUpgrade libqpdf26Upgrade cups-filters-foomatic-ripUpgrade libqpdf18Upgrade qpdfUpgrade libqpdf28Upgrade cups-filtersUpgrade cups-filters-cups-browsed | Feb 20, 2018 | Aug 27, 2017 |
| Ubuntu | — | Upgrade qpdfUpgrade libqpdf21 | May 15, 2018 | Aug 27, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub