libqpdf.a in QPDF through 8.0.2 mishandles certain "expected dictionary key but found non-name object" cases, allowing remote attackers to cause a denial of service (stack exhaustion), related to the QPDFObjectHandle and QPDF_Dictionary classes, because nesting in direct objects is not restricted.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade qpdf | Jul 30, 2024 | Apr 10, 2018 |
| Oracle Solaris | — | Upgrade print/qpdf to version 8.2.1-11.4.5.0.1.2.0 on Solaris 11.4 | Feb 20, 2019 | Apr 10, 2018 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Apr 10, 2018 |
| Suse | — | Upgrade libqpdf18Upgrade qpdf-develUpgrade qpdf | Aug 9, 2024 | Apr 10, 2018 |
| Ubuntu | — | Upgrade libqpdf21Upgrade qpdf | May 15, 2018 | Apr 10, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub