CVE-2017-18183: Medium severity Qpdf Project Qpdf vulnerability
An issue was discovered in QPDF before 7.0.0. There is an infinite loop in the QPDFWriter::enqueueObject() function in libqpdf/QPDFWriter.cc.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/qpdfto a version that resolves this vulnerability.Fixed in 10.1.0-1Fixed in 11.3.0-1+deb12u1Fixed in 12.2.0-1Fixed in 12.3.2-1 - Upgrade
Upgrade
qpdfto a version that resolves this vulnerability.Fixed in 7.0.0
Event History
Frequently Asked Questions
What is the severity of CVE-2017-18183?
CVE-2017-18183 has a low severity due to the insufficient consequences of the infinite loop in QPDF.
How do I fix CVE-2017-18183?
To fix CVE-2017-18183, upgrade to QPDF version 7.0.0 or later.
Which versions of QPDF are affected by CVE-2017-18183?
All versions of QPDF prior to 7.0.0 are affected by CVE-2017-18183.
What type of issue is CVE-2017-18183?
CVE-2017-18183 is an infinite loop vulnerability found in the QPDFWriter::enqueueObject() function.
Is there any known workaround for CVE-2017-18183?
There are no documented workarounds for CVE-2017-18183; the only solution is to update the software.