4.3
CVSSv2

CVE-2015-9252

Published: 13/02/2018 Updated: 08/05/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

An issue exists in QPDF prior to 7.0.0. Endless recursion causes stack exhaustion in QPDFTokenizer::resolveLiteral() in QPDFTokenizer.cc, related to the QPDF::resolve function in QPDF.cc.

Vulnerable Product Search on Vulmon Subscribe to Product

qpdf project qpdf

Vendor Advisories

Several security issues were fixed in QPDF ...
An issue was discovered in QPDF before 700 Endless recursion causes stack exhaustion in QPDFTokenizer::resolveLiteral() in QPDFTokenizercc, related to the QPDF::resolve function in QPDFcc ...