4.3
CVSSv2

CVE-2021-36978

Published: 20/07/2021 Updated: 15/01/2024
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

QPDF 9.x up to and including 9.1.1 and 10.x up to and including 10.0.4 has a heap-based buffer overflow in Pl_ASCII85Decoder::write (called from Pl_AES_PDF::flush and Pl_AES_PDF::finish) when a certain downstream write fails.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

qpdf project qpdf

Vendor Advisories

QPDF 9x through 911 and 10x through 1004 has a heap-based buffer overflow in Pl_ASCII85Decoder::write (called from Pl_AES_PDF::flush and Pl_AES_PDF::finish) when a certain downstream write fails (CVE-2021-36978) ...