CVE-2021-25786: Use After Free
Published Aug 11, 2023
·Updated
An issue was discovered in QPDF version 10.0.4, allows remote attackers to execute arbitrary code via crafted .pdf file to PlASCII85Decoder::write parameter in libqpdf.
Affected Software
1 affected component
Qpdf Project Qpdf=10.0.4
Remediation
Patch Available
Event History
Aug 11, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-25786?
CVE-2021-25786 has a high severity rating due to its potential for remote code execution.
2
How do I fix CVE-2021-25786?
To fix CVE-2021-25786, update QPDF to version 10.1.0 or later, which includes patches for this vulnerability.
3
What types of attacks can exploit CVE-2021-25786?
CVE-2021-25786 can be exploited by sending a specially crafted PDF file to target users, leading to arbitrary code execution.
4
Which software versions are affected by CVE-2021-25786?
CVE-2021-25786 specifically affects QPDF version 10.0.4.
5
Is CVE-2021-25786 manageable on my network?
Yes, CVE-2021-25786 can be managed by ensuring that all users have upgraded to the patched version of QPDF and by monitoring for potential exploitation attempts.