First published: Mon May 07 2018(Updated: )
It was discovered that QPDF incorrectly handled certain malformed files. A remote attacker could use this issue to cause QPDF to crash, resulting in a denial of service, or possibly execute arbitrary code.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libqpdf21 | <8.0.2-3~17.10.1 | 8.0.2-3~17.10.1 |
Ubuntu OpenSSH Client | =17.10 | |
All of | ||
ubuntu/qpdf | <8.0.2-3~17.10.1 | 8.0.2-3~17.10.1 |
Ubuntu OpenSSH Client | =17.10 | |
All of | ||
ubuntu/libqpdf21 | <8.0.2-3~16.04.1 | 8.0.2-3~16.04.1 |
Ubuntu OpenSSH Client | =16.04 | |
All of | ||
ubuntu/qpdf | <8.0.2-3~16.04.1 | 8.0.2-3~16.04.1 |
Ubuntu OpenSSH Client | =16.04 | |
All of | ||
ubuntu/libqpdf21 | <8.0.2-3~14.04.1 | 8.0.2-3~14.04.1 |
Ubuntu OpenSSH Client | =14.04 | |
All of | ||
ubuntu/qpdf | <8.0.2-3~14.04.1 | 8.0.2-3~14.04.1 |
Ubuntu OpenSSH Client | =14.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)
USN-3638-1 has a severity rating that indicates it can cause denial of service or potential arbitrary code execution.
To fix USN-3638-1, upgrade to the updated package versions 8.0.2-3~17.10.1, 8.0.2-3~16.04.1, or 8.0.2-3~14.04.1 for libqpdf21 and qpdf.
No, only specific versions of Ubuntu, including 14.04, 16.04, and 17.10, with the affected packages are vulnerable to USN-3638-1.
The potential impact of USN-3638-1 includes application crashes leading to a denial of service and the possibility of arbitrary code execution.
The affected packages in USN-3638-1 are libqpdf21 and qpdf in the specified Ubuntu versions.