CVE-2022-34503: Buffer Overflow
Published Jul 22, 2022
·Updated
QPDF v8.4.2 was discovered to contain a heap buffer overflow via the function QPDF::processXRefStream. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.
Affected Software
1 affected component
Qpdf Project Qpdf=8.4.2
Event History
Jul 22, 2022
CVE Published
via MITRE·02:17 PM
Data Sourced
via MITRE·02:17 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-34503?
CVE-2022-34503 is classified as a high severity vulnerability due to its potential to cause Denial of Service.
2
How do I fix CVE-2022-34503?
To fix CVE-2022-34503, update QPDF to version 8.4.3 or later.
3
What type of vulnerability is CVE-2022-34503?
CVE-2022-34503 is a heap buffer overflow vulnerability.
4
What can an attacker do with CVE-2022-34503?
An attacker can exploit CVE-2022-34503 to cause a Denial of Service by using a crafted PDF file.
5
Which software versions are affected by CVE-2022-34503?
CVE-2022-34503 affects QPDF version 8.4.2 specifically.