First published: Mon Mar 25 2024(Updated: )
It was discovered that QPDF incorrectly handled certain memory operations when decoding JSON files. If a user or automated system were tricked into processing a specially crafted JSON file, QPDF could be made to crash, resulting in a denial of service, or possibly execute arbitrary code.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/libqpdf29 | <11.5.0-1ubuntu1.1 | 11.5.0-1ubuntu1.1 |
Ubuntu | =23.10 | |
All of | ||
ubuntu/qpdf | <11.5.0-1ubuntu1.1 | 11.5.0-1ubuntu1.1 |
Ubuntu | =23.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
USN-6713-1 is classified as a vulnerability that can lead to denial of service due to improper memory handling in QPDF.
To fix USN-6713-1, update the affected packages libqpdf29 and qpdf to the version 11.5.0-1ubuntu1.1 or later.
USN-6713-1 affects Ubuntu 23.10 when running the specified versions of libqpdf29 and qpdf.
USN-6713-1 could potentially allow attackers to crash applications or execute arbitrary code through specially crafted JSON files.
Currently, the best approach to mitigate USN-6713-1 is to immediately upgrade the affected software to the recommended version.