CVE-2017-9208: Medium severity Qpdf Project Qpdf vulnerability
Last updated 25 August 2025
Other sources
libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) via a crafted PDF document, related to releaseResolved functions, aka qpdf-infiniteloop1.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/qpdfto a version that resolves this vulnerability.Fixed in 10.1.0-1Fixed in 11.3.0-1+deb12u1Fixed in 12.2.0-1Fixed in 12.3.2-1 - Upgrade
Upgrade
QPDFto a version that resolves this vulnerability.Fixed in 6.0.0Patch qpdf-infiniteloop1 - Compensating control
Mitigate remote DoS risk from crafted PDFs by restricting access/inputs to QPDF processing (e.g., only process trusted PDFs and/or block untrusted upload sources) until the affected version is patched.
Event History
Frequently Asked Questions
What is the severity of CVE-2017-9208?
CVE-2017-9208 is classified as a denial of service vulnerability due to infinite recursion and stack consumption.
How do I fix CVE-2017-9208?
To fix CVE-2017-9208, upgrade to a patched version of QPDF such as 8.0.2-3~14.04.1 or a later release.
Which versions of QPDF are affected by CVE-2017-9208?
Versions of QPDF prior to 8.0.2 and including 6.0.0 are affected by CVE-2017-9208.
What type of attack does CVE-2017-9208 facilitate?
CVE-2017-9208 facilitates a denial of service attack through the use of specially crafted PDF documents.
Is CVE-2017-9208 specific to any operating systems?
CVE-2017-9208 is primarily associated with Ubuntu and Debian builds of the QPDF software.