CVE-2017-18186Infinite Loop in Project Qpdf

Severity
5.5MEDIUMNVD
EPSS
0.3%
top 44.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 13
Latest updateMay 13

Description

An issue was discovered in QPDF before 7.0.0. There is an infinite loop due to looping xref tables in QPDF.cc.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

NVDqpdf_project/qpdf< 7.0.0
Debianqpdf_project/qpdf< 7.0.0-1+3

🔴Vulnerability Details

3
GHSA
GHSA-v5gm-hmrc-rgfq: An issue was discovered in QPDF before 72022-05-13
OSV
CVE-2017-18186: An issue was discovered in QPDF before 72018-02-13
CVEList
CVE-2017-18186: An issue was discovered in QPDF before 72018-02-13

📋Vendor Advisories

3
Ubuntu
QPDF vulnerabilities2018-05-07
Red Hat
qpdf: infinite loop due to looping xref tables in QPDF.cc2017-08-24
Debian
CVE-2017-18186: qpdf - An issue was discovered in QPDF before 7.0.0. There is an infinite loop due to l...2017

💬Community

1
Bugzilla
CVE-2017-18186 qpdf: infinite loop due to looping xref tables in QPDF.cc2018-02-14
CVE-2017-18186 — Infinite Loop in Qpdf Project Qpdf | cvebase