Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown
CVE-2017-12595
Disclosure Date: August 27, 2017 (last updated November 26, 2024)
The tokenizer in QPDF 6.0.0 and 7.0.b1 is recursive for arrays and dictionaries, which allows remote attackers to cause a denial of service (stack consumption and segmentation fault) or possibly have unspecified other impact via a PDF document with a deep data structure, as demonstrated by a crash in QPDFObjectHandle::parseInternal in libqpdf/QPDFObjectHandle.cc.
0
Attacker Value
Unknown
CVE-2017-11625
Disclosure Date: July 25, 2017 (last updated November 26, 2024)
A stack-consumption vulnerability was found in libqpdf in QPDF 6.0.0, which allows attackers to cause a denial of service via a crafted file, related to the QPDF::resolveObjectsInStream function in QPDF.cc, aka an "infinite loop."
0
Attacker Value
Unknown
CVE-2017-11626
Disclosure Date: July 25, 2017 (last updated November 26, 2024)
A stack-consumption vulnerability was found in libqpdf in QPDF 6.0.0, which allows attackers to cause a denial of service via a crafted file, related to the QPDFTokenizer::resolveLiteral function in QPDFTokenizer.cc after four consecutive calls to QPDFObjectHandle::parseInternal, aka an "infinite loop."
0
Attacker Value
Unknown
CVE-2017-11627
Disclosure Date: July 25, 2017 (last updated November 26, 2024)
A stack-consumption vulnerability was found in libqpdf in QPDF 6.0.0, which allows attackers to cause a denial of service via a crafted file, related to the PointerHolder function in PointerHolder.hh, aka an "infinite loop."
0
Attacker Value
Unknown
CVE-2017-11624
Disclosure Date: July 25, 2017 (last updated November 26, 2024)
A stack-consumption vulnerability was found in libqpdf in QPDF 6.0.0, which allows attackers to cause a denial of service via a crafted file, related to the QPDFTokenizer::resolveLiteral function in QPDFTokenizer.cc after two consecutive calls to QPDFObjectHandle::parseInternal, aka an "infinite loop."
0
Attacker Value
Unknown
CVE-2017-9209
Disclosure Date: May 23, 2017 (last updated November 26, 2024)
libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) via a crafted PDF document, related to QPDFObjectHandle::parseInternal, aka qpdf-infiniteloop2.
0
Attacker Value
Unknown
CVE-2017-9208
Disclosure Date: May 23, 2017 (last updated November 26, 2024)
libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) via a crafted PDF document, related to releaseResolved functions, aka qpdf-infiniteloop1.
0
Attacker Value
Unknown
CVE-2017-9210
Disclosure Date: May 23, 2017 (last updated November 26, 2024)
libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) via a crafted PDF document, related to unparse functions, aka qpdf-infiniteloop3.
0