vulnerability

SUSE: CVE-2017-11624: SUSE Linux Security Advisory

Severity
4
CVSS
(AV:N/AC:M/Au:N/C:N/I:N/A:P)
Published
Jul 25, 2017
Added
Feb 20, 2018
Modified
Feb 4, 2022

Description

A stack-consumption vulnerability was found in libqpdf in QPDF 6.0.0, which allows attackers to cause a denial of service via a crafted file, related to the QPDFTokenizer::resolveLiteral function in QPDFTokenizer.cc after two consecutive calls to QPDFObjectHandle::parseInternal, aka an "infinite loop."

Solution(s)

suse-upgrade-cups-filterssuse-upgrade-cups-filters-cups-browsedsuse-upgrade-cups-filters-foomatic-ripsuse-upgrade-cups-filters-ghostscriptsuse-upgrade-libqpdf18suse-upgrade-libqpdf21suse-upgrade-libqpdf26suse-upgrade-libqpdf28suse-upgrade-qpdfsuse-upgrade-qpdf-devel
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.