CVE-2017-12595: Input Validation
Last updated 25 August 2025
Other sources
The tokenizer in QPDF 6.0.0 and 7.0.b1 is recursive for arrays and dictionaries, which allows remote attackers to cause a denial of service (stack consumption and segmentation fault) or possibly have unspecified other impact via a PDF document with a deep data structure, as demonstrated by a crash in QPDFObjectHandle::parseInternal in libqpdf/QPDFObjectHandle.cc.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/qpdfto a version that resolves this vulnerability.Fixed in 10.1.0-1Fixed in 11.3.0-1+deb12u1Fixed in 12.2.0-1Fixed in 12.3.2-1
Event History
Frequently Asked Questions
What is the severity of CVE-2017-12595?
CVE-2017-12595 has a high severity rating due to its potential to cause denial of service through stack consumption.
How do I fix CVE-2017-12595?
To fix CVE-2017-12595, update to QPDF version 8.0.2-3~14.04.1 or higher.
Which software versions are affected by CVE-2017-12595?
CVE-2017-12595 affects QPDF versions 6.0.0 to 7.0.b1.
What impact does CVE-2017-12595 have?
CVE-2017-12595 can lead to a crash and segmentation fault when processing specific PDF documents.
Is CVE-2017-12595 a product-specific vulnerability?
Yes, CVE-2017-12595 is specific to the QPDF library used in various applications for handling PDF files.