CVE-2017-11627: Medium severity Qpdf Project Qpdf vulnerability
A stack-consumption vulnerability was found in libqpdf in QPDF 6.0.0, which allows attackers to cause a denial of service via a crafted file, related to the PointerHolder function in PointerHolder.hh, aka an "infinite loop."
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/qpdfto a version that resolves this vulnerability.Fixed in 10.1.0-1Fixed in 11.3.0-1+deb12u1Fixed in 12.2.0-1Fixed in 12.3.2-1 - Upgrade
Upgrade
libqpdf (QPDF)to a version that resolves this vulnerability.Fixed in 6.0.0
Event History
Frequently Asked Questions
What is the severity of CVE-2017-11627?
CVE-2017-11627 is classified as a denial of service vulnerability due to stack consumption.
How do I fix CVE-2017-11627?
To fix CVE-2017-11627, upgrade to a patched version of qpdf that is listed in the affected software section.
What software is affected by CVE-2017-11627?
CVE-2017-11627 affects qpdf version 6.0.0 and prior versions in various distributions.
Can CVE-2017-11627 be exploited remotely?
Yes, CVE-2017-11627 can be exploited remotely via crafted files causing denial of service.
What impact does CVE-2017-11627 have on system performance?
CVE-2017-11627 can cause degradation in system performance by entering an infinite loop.