First published: Fri Aug 11 2023(Updated: )
An issue was discovered in QPDF version 10.0.4, allows remote attackers to execute arbitrary code via crafted .pdf file to Pl_ASCII85Decoder::write parameter in libqpdf.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
qpdf | =10.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25786 has a high severity rating due to its potential for remote code execution.
To fix CVE-2021-25786, update QPDF to version 10.1.0 or later, which includes patches for this vulnerability.
CVE-2021-25786 can be exploited by sending a specially crafted PDF file to target users, leading to arbitrary code execution.
CVE-2021-25786 specifically affects QPDF version 10.0.4.
Yes, CVE-2021-25786 can be managed by ensuring that all users have upgraded to the patched version of QPDF and by monitoring for potential exploitation attempts.