CVE-2015-9252: Medium severity qpdf vulnerability
Published Feb 13, 2018
·Updated
An issue was discovered in QPDF before 7.0.0. Endless recursion causes stack exhaustion in QPDFTokenizer::resolveLiteral() in QPDFTokenizer.cc, related to the QPDF::resolve function in QPDF.cc.
Affected Software
5 affected componentsFixes available
ubuntu/qpdf<8.0.2-3~14.04.1
8.0.2-3~14.04.1
ubuntu/qpdf<7.0.0-1
7.0.0-1
ubuntu/qpdf<8.0.2-3~16.04.1
8.0.2-3~16.04.1
debian/qpdf
10.1.0-111.3.0-1+deb12u111.9.1-1
Qpdf Project Qpdf<7.0.0
Remediation
Event History
Feb 13, 2018
CVE Published
via Ubuntu·12:00 AM
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:13 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-9252?
CVE-2015-9252 has a medium severity due to the potential for denial of service caused by stack exhaustion.
2
How do I fix CVE-2015-9252?
To fix CVE-2015-9252, upgrade to QPDF version 7.0.0 or later.
3
Which versions of QPDF are affected by CVE-2015-9252?
QPDF versions prior to 7.0.0 are vulnerable to CVE-2015-9252.
4
Can CVE-2015-9252 lead to Denial of Service?
Yes, CVE-2015-9252 can cause Denial of Service due to endless recursion leading to stack exhaustion.
5
Is CVE-2015-9252 a critical vulnerability?
No, CVE-2015-9252 is not considered critical but has potential impacts that should be addressed.