CVE-2017-18183Infinite Loop in Project Qpdf

Severity
5.5MEDIUMNVD
EPSS
0.3%
top 43.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 13
Latest updateMay 13

Description

An issue was discovered in QPDF before 7.0.0. There is an infinite loop in the QPDFWriter::enqueueObject() function in libqpdf/QPDFWriter.cc.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

NVDqpdf_project/qpdf< 7.0.0
Debianqpdf_project/qpdf< 7.0.0-1+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-c873-f884-8r22: An issue was discovered in QPDF before 72022-05-13
OSV
CVE-2017-18183: An issue was discovered in QPDF before 72018-02-13
CVEList
CVE-2017-18183: An issue was discovered in QPDF before 72018-02-13

📋Vendor Advisories

3
Ubuntu
QPDF vulnerabilities2018-05-07
Red Hat
qpdf: Infinite Loop in QPDFWriter::enqueueObject in libqpdf/QPDFWriter.cc2017-08-12
Debian
CVE-2017-18183: qpdf - An issue was discovered in QPDF before 7.0.0. There is an infinite loop in the Q...2017

💬Community

1
Bugzilla
CVE-2017-18183 qpdf: Infinite Loop in QPDFWriter::enqueueObject in libqpdf/QPDFWriter.cc2018-02-14
CVE-2017-18183 — Infinite Loop in Qpdf Project Qpdf | cvebase