4.3
CVSSv2

CVE-2017-18185

Published: 13/02/2018 Updated: 08/05/2018
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

An issue exists in QPDF prior to 7.0.0. There is a large heap-based out-of-bounds read in the Pl_Buffer::write function in Pl_Buffer.cc. It is caused by an integer overflow in the PNG filter.

Vulnerable Product Search on Vulmon Subscribe to Product

qpdf project qpdf

Vendor Advisories

Several security issues were fixed in QPDF ...
An integer overflow flaw leading to heap-based out-of-bounds read was found in the way QPDF parsed PDF files An attacker could potentially use this flaw to crash QPDF by tricking it into processing crafted QPDF files ...
An issue was discovered in QPDF before 700 There is a large heap-based out-of-bounds read in the Pl_Buffer::write function in Pl_Buffercc It is caused by an integer overflow in the PNG filter ...