CVE-2015-9252Uncontrolled Resource Consumption in Project Qpdf

Severity
5.5MEDIUMNVD
EPSS
0.3%
top 45.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 13
Latest updateMay 14

Description

An issue was discovered in QPDF before 7.0.0. Endless recursion causes stack exhaustion in QPDFTokenizer::resolveLiteral() in QPDFTokenizer.cc, related to the QPDF::resolve function in QPDF.cc.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

NVDqpdf_project/qpdf< 7.0.0
Debianqpdf_project/qpdf< 7.0.0-1+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-8xcr-vf9j-wxvr: An issue was discovered in QPDF before 72022-05-14
CVEList
CVE-2015-9252: An issue was discovered in QPDF before 72018-02-13
OSV
CVE-2015-9252: An issue was discovered in QPDF before 72018-02-13

📋Vendor Advisories

3
Ubuntu
QPDF vulnerabilities2018-05-07
Red Hat
qpdf: Infinite loop in QPDFTokenizer::resolveLiteral in QPDFTokenizer.cc2015-09-02
Debian
CVE-2015-9252: qpdf - An issue was discovered in QPDF before 7.0.0. Endless recursion causes stack exh...2015

💬Community

1
Bugzilla
CVE-2015-9252 qpdf: Infinite loop in QPDFTokenizer::resolveLiteral in QPDFTokenizer.cc2018-02-14
CVE-2015-9252 — Uncontrolled Resource Consumption | cvebase