CVE-2017-18185: Integer Overflow
An issue was discovered in QPDF before 7.0.0. There is a large heap-based out-of-bounds read in the PlBuffer::write function in PlBuffer.cc. It is caused by an integer overflow in the PNG filter.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/qpdfto a version that resolves this vulnerability.Fixed in 10.1.0-1Fixed in 11.3.0-1+deb12u1Fixed in 12.2.0-1Fixed in 12.3.2-1 - Upgrade
Upgrade
qpdfto a version that resolves this vulnerability.Fixed in 7.0.0
Event History
Frequently Asked Questions
What is the severity of CVE-2017-18185?
CVE-2017-18185 has been classified as a high severity vulnerability due to its large heap-based out-of-bounds read potential.
How do I fix CVE-2017-18185?
To fix CVE-2017-18185, update QPDF to version 7.0.0 or later, or to specific secure versions like 8.0.2-3~14.04.1 for Ubuntu.
What software is affected by CVE-2017-18185?
CVE-2017-18185 affects QPDF versions prior to 7.0.0.
What type of vulnerability is CVE-2017-18185?
CVE-2017-18185 is a heap-based out-of-bounds read vulnerability caused by an integer overflow in the PNG filter.
What should I do if I cannot update to a fixed version for CVE-2017-18185?
If you cannot update, you should apply security best practices and mitigate potential exploits by restricting access to the vulnerable software.