CVE-2017-18184: Medium severity Qpdf Project Qpdf vulnerability
An issue was discovered in QPDF before 7.0.0. There is a stack-based out-of-bounds read in the function iteraterc4 in QPDFencryption.cc.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/qpdfto a version that resolves this vulnerability.Fixed in 10.1.0-1Fixed in 11.3.0-1+deb12u1Fixed in 12.2.0-1Fixed in 12.3.2-1 - Upgrade
Upgrade
QPDFto a version that resolves this vulnerability.Fixed in 7.0.0
Event History
Frequently Asked Questions
What is the severity of CVE-2017-18184?
CVE-2017-18184 is considered a high severity vulnerability due to the potential for stack-based out-of-bounds read exploits.
How do I fix CVE-2017-18184?
To mitigate CVE-2017-18184, upgrade to QPDF version 7.0.0 or later, or to any recommended patched version provided by your distribution.
What software is affected by CVE-2017-18184?
CVE-2017-18184 affects QPDF versions before 7.0.0.
What is the nature of CVE-2017-18184?
CVE-2017-18184 involves a stack-based out-of-bounds read vulnerability in the function iterate_rc4 in QPDF_encryption.cc.
Has CVE-2017-18184 been exploited in the wild?
As of the last updates, there are no widely reported cases of CVE-2017-18184 being actively exploited in the wild.