4.3
CVSSv2

CVE-2017-18184

Published: 13/02/2018 Updated: 08/05/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

An issue exists in QPDF prior to 7.0.0. There is a stack-based out-of-bounds read in the function iterate_rc4 in QPDF_encryption.cc.

Vulnerable Product Search on Vulmon Subscribe to Product

qpdf project qpdf

Vendor Advisories

Several security issues were fixed in QPDF ...
A stack-based out-of-bounds read flaw was found in the way QPDF parsed PDF files An attacker could potentially use this flaw to crash QPDF, under certain conditions, by tricking it into processing crafted QPDF files ...
An issue was discovered in QPDF before 700 There is a stack-based out-of-bounds read in the function iterate_rc4 in QPDF_encryptioncc ...