CVE-2017-11625: Medium severity qpdf vulnerability
Published Jul 25, 2017
·Updated
A stack-consumption vulnerability was found in libqpdf in QPDF 6.0.0, which allows attackers to cause a denial of service via a crafted file, related to the QPDF::resolveObjectsInStream function in QPDF.cc, aka an "infinite loop."
Affected Software
5 affected componentsFixes available
ubuntu/qpdf<8.0.2-3~14.04.1
8.0.2-3~14.04.1
ubuntu/qpdf<7.0.0-1
7.0.0-1
ubuntu/qpdf<8.0.2-3~16.04.1
8.0.2-3~16.04.1
debian/qpdf
10.1.0-111.3.0-1+deb12u111.9.1-1
Qpdf Project Qpdf=6.0.0
Remediation
Event History
Jul 25, 2017
CVE Published
via Ubuntu·12:00 AM
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:26 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-11625?
CVE-2017-11625 has a severity rating classified as a denial of service vulnerability.
2
How do I fix CVE-2017-11625?
To mitigate CVE-2017-11625, upgrade to QPDF version 8.0.2-3~14.04.1 or later.
3
What software is affected by CVE-2017-11625?
CVE-2017-11625 affects QPDF versions 6.0.0 through earlier versions up to 8.0.2-3~14.04.1.
4
What type of vulnerability is CVE-2017-11625?
CVE-2017-11625 is a stack-consumption vulnerability that can lead to an infinite loop.
5
What is the impact of CVE-2017-11625?
The impact of CVE-2017-11625 is that it allows attackers to create a denial of service condition through crafted files.