CVE-2017-9210: Medium severity Qpdf Project Qpdf vulnerability
Last updated 25 August 2025
Other sources
libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) via a crafted PDF document, related to unparse functions, aka qpdf-infiniteloop3.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/qpdfto a version that resolves this vulnerability.Fixed in 10.1.0-1Fixed in 11.3.0-1+deb12u1Fixed in 12.2.0-1Fixed in 12.3.2-1 - Upgrade
Upgrade
QPDFto a version that resolves this vulnerability.Fixed in 6.0.0Patch qpdf-infiniteloop3
Event History
Frequently Asked Questions
What is the severity of CVE-2017-9210?
CVE-2017-9210 is classified as a denial of service vulnerability that can lead to infinite recursion and stack consumption.
How do I fix CVE-2017-9210?
To mitigate CVE-2017-9210, upgrade to QPDF version 8.0.2-3~14.04.1 or a later version.
What software is affected by CVE-2017-9210?
CVE-2017-9210 affects QPDF versions prior to 8.0.2-3~14.04.1, including version 6.0.0.
Can CVE-2017-9210 be exploited remotely?
Yes, CVE-2017-9210 can be exploited remotely via a crafted PDF document.
What is the impact of CVE-2017-9210?
The impact of CVE-2017-9210 is a denial of service that prevents the affected application from functioning properly.