CVE-2017-9209: Medium severity Qpdf Project Qpdf vulnerability
Last updated 25 August 2025
Other sources
libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) via a crafted PDF document, related to QPDFObjectHandle::parseInternal, aka qpdf-infiniteloop2.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/qpdfto a version that resolves this vulnerability.Fixed in 10.1.0-1Fixed in 11.3.0-1+deb12u1Fixed in 12.2.0-1Fixed in 12.3.2-1 - Compensating control
Mitigate CVE described as “qpdf-infiniteloop2”: use a compensating control by blocking or limiting access to QPDF processing of untrusted/crafted PDF documents until a fixed QPDF version or patch is applied.
Event History
Frequently Asked Questions
What is the severity of CVE-2017-9209?
CVE-2017-9209 has a moderate severity level due to its potential to cause denial of service.
How do I fix CVE-2017-9209?
To fix CVE-2017-9209, upgrade QPDF to version 8.0.2-3~14.04.1 or later.
Which versions of QPDF are affected by CVE-2017-9209?
CVE-2017-9209 affects QPDF version 6.0.0 and prior versions.
What types of attacks does CVE-2017-9209 allow?
CVE-2017-9209 allows remote attackers to trigger infinite recursion and stack consumption through crafted PDF documents.
Are there any specific operating systems vulnerable to CVE-2017-9209?
CVE-2017-9209 affects Ubuntu versions 14.04, 16.04, and 17.10 when using the vulnerable QPDF package.