CVE-2018-18020
published 2018-10-06CVE-2018-18020: In QPDF 8.2.1, in libqpdf/QPDFWriter.cc, QPDFWriter::unparseObject and QPDFWriter::unparseChild have recursive calls for a long time, which allows remote…
PriorityP48low3.3CVSS 3.0
AVLACLPRNUIRSUCNINAL
EPSS
1.28%
66.8th percentile
In QPDF 8.2.1, in libqpdf/QPDFWriter.cc, QPDFWriter::unparseObject and QPDFWriter::unparseChild have recursive calls for a long time, which allows remote attackers to cause a denial of service via a crafted PDF file.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | qpdf | < qpdf 9.0.0-1 (bookworm) | qpdf 9.0.0-1 (bookworm) |
| qpdf_project | qpdf | — | — |
| qpdf_project | qpdf | >= 0 < 9.0.0-1 | 9.0.0-1 |
| qpdf_project | qpdf | >= 0 < 9.0.0-1 | 9.0.0-1 |
| qpdf_project | qpdf | >= 0 < 9.0.0-1 | 9.0.0-1 |
| qpdf_project | qpdf | >= 0 < 9.0.0-1 | 9.0.0-1 |
| qpdf_project | qpdf | >= 0 < 8.0.2-3ubuntu0.1 | 8.0.2-3ubuntu0.1 |
| qpdf_project | qpdf | >= 0 < 9.1.1-1ubuntu0.1 | 9.1.1-1ubuntu0.1 |
| qpdf_project | qpdf | >= 0 < 8.0.2-3~16.04.1+esm1 | 8.0.2-3~16.04.1+esm1 |
CVSS provenance
nvdv3.03.3LOWCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv3.3LOW
vendor_debian3.3LOW
vendor_redhat3.3LOW
vendor_ubuntu3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
QPDF vulnerabilities
vendor_ubuntu·2021-08-02·CVSS 3.3
CVE-2021-36978 [LOW] QPDF vulnerabilities
Title: QPDF vulnerabilities
Summary: Several security issues were fixed in QPDF.
USN-5026-1 fixed several vulnerabilities in QPDF. This update provides
the corresponding update for Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that QPDF incorrectly handled certain malformed PDF
files. A remote attacker could use this issue to cause QPDF to consume
resources, resulting in a denial of service. (CVE-2018-18020)
It was discovered that QPDF incorrectly handled certain malformed PDF
files. A remote attacker could use this issue to cause QPDF to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2021-36978)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
QPDF vulnerabilities
vendor_ubuntu·2021-07-29·CVSS 3.3
CVE-2018-18020 [LOW] QPDF vulnerabilities
Title: QPDF vulnerabilities
Summary: Several security issues were fixed in QPDF.
It was discovered that QPDF incorrectly handled certain malformed PDF
files. A remote attacker could use this issue to cause QPDF to consume
resources, resulting in a denial of service. This issue only affected
Ubuntu 18.04 LTS. (CVE-2018-18020)
It was discovered that QPDF incorrectly handled certain malformed PDF
files. A remote attacker could use this issue to cause QPDF to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2021-36978)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
qpdf: recursive calls can lead to a DoS in libqpdf/QPDFWriter.cc
vendor_redhat·2018-10-06·CVSS 3.3
CVE-2018-18020 [LOW] CWE-400 qpdf: recursive calls can lead to a DoS in libqpdf/QPDFWriter.cc
qpdf: recursive calls can lead to a DoS in libqpdf/QPDFWriter.cc
In QPDF 8.2.1, in libqpdf/QPDFWriter.cc, QPDFWriter::unparseObject and QPDFWriter::unparseChild have recursive calls for a long time, which allows remote attackers to cause a denial of service via a crafted PDF file.
Package: qpdf (Red Hat Enterprise Linux 7) - Not affected
Package: qpdf (Red Hat Enterprise Linux 8) - Fix deferred
Debian
CVE-2018-18020: qpdf - In QPDF 8.2.1, in libqpdf/QPDFWriter.cc, QPDFWriter::unparseObject and QPDFWrite...
vendor_debian·2018·CVSS 3.3
CVE-2018-18020 [LOW] CVE-2018-18020: qpdf - In QPDF 8.2.1, in libqpdf/QPDFWriter.cc, QPDFWriter::unparseObject and QPDFWrite...
In QPDF 8.2.1, in libqpdf/QPDFWriter.cc, QPDFWriter::unparseObject and QPDFWriter::unparseChild have recursive calls for a long time, which allows remote attackers to cause a denial of service via a crafted PDF file.
Scope: local
bookworm: resolved (fixed in 9.0.0-1)
bullseye: resolved (fixed in 9.0.0-1)
forky: resolved (fixed in 9.0.0-1)
sid: resolved (fixed in 9.0.0-1)
trixie: resolved (fixed in 9.0.0-1)
GHSA
GHSA-r676-q927-78rr: In QPDF 8
ghsa_unreviewed·2022-05-13
CVE-2018-18020 [MEDIUM] CWE-674 GHSA-r676-q927-78rr: In QPDF 8
In QPDF 8.2.1, in libqpdf/QPDFWriter.cc, QPDFWriter::unparseObject and QPDFWriter::unparseChild have recursive calls for a long time, which allows remote attackers to cause a denial of service via a crafted PDF file.
OSV
qpdf vulnerabilities
osv·2021-08-02·CVSS 3.3
CVE-2018-18020 [LOW] qpdf vulnerabilities
qpdf vulnerabilities
USN-5026-1 fixed several vulnerabilities in QPDF. This update provides
the corresponding update for Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that QPDF incorrectly handled certain malformed PDF
files. A remote attacker could use this issue to cause QPDF to consume
resources, resulting in a denial of service. (CVE-2018-18020)
It was discovered that QPDF incorrectly handled certain malformed PDF
files. A remote attacker could use this issue to cause QPDF to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2021-36978)
OSV
qpdf vulnerabilities
osv·2021-07-29·CVSS 3.3
CVE-2018-18020 [LOW] qpdf vulnerabilities
qpdf vulnerabilities
It was discovered that QPDF incorrectly handled certain malformed PDF
files. A remote attacker could use this issue to cause QPDF to consume
resources, resulting in a denial of service. This issue only affected
Ubuntu 18.04 LTS. (CVE-2018-18020)
It was discovered that QPDF incorrectly handled certain malformed PDF
files. A remote attacker could use this issue to cause QPDF to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2021-36978)
OSV
CVE-2018-18020: In QPDF 8
osv·2018-10-06·CVSS 3.3
CVE-2018-18020 [LOW] CVE-2018-18020: In QPDF 8
In QPDF 8.2.1, in libqpdf/QPDFWriter.cc, QPDFWriter::unparseObject and QPDFWriter::unparseChild have recursive calls for a long time, which allows remote attackers to cause a denial of service via a crafted PDF file.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-18020 qpdf: recursive calls can lead to a DoS in libqpdf/QPDFWriter.cc [epel-6]
bugzilla·2018-11-05·CVSS 3.3
CVE-2018-18020 [LOW] CVE-2018-18020 qpdf: recursive calls can lead to a DoS in libqpdf/QPDFWriter.cc [epel-6]
CVE-2018-18020 qpdf: recursive calls can lead to a DoS in libqpdf/QPDFWriter.cc [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-6.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following template to fo
Bugzilla
CVE-2018-18020 qpdf: recursive calls can lead to a DoS in libqpdf/QPDFWriter.cc [fedora-all]
bugzilla·2018-11-05·CVSS 3.3
CVE-2018-18020 [LOW] CVE-2018-18020 qpdf: recursive calls can lead to a DoS in libqpdf/QPDFWriter.cc [fedora-all]
CVE-2018-18020 qpdf: recursive calls can lead to a DoS in libqpdf/QPDFWriter.cc [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple sup
Bugzilla
CVE-2018-18020 qpdf: recursive calls can lead to a DoS in libqpdf/QPDFWriter.cc
bugzilla·2018-11-05·CVSS 3.3
CVE-2018-18020 [LOW] CVE-2018-18020 qpdf: recursive calls can lead to a DoS in libqpdf/QPDFWriter.cc
CVE-2018-18020 qpdf: recursive calls can lead to a DoS in libqpdf/QPDFWriter.cc
A flaw was found in QPDF 8.2.1, in libqpdf/QPDFWriter.cc, QPDFWriter::unparseObject and QPDFWriter::unparseChild have recursive calls for a long time, which allows remote attackers to cause a denial of service via a crafted PDF file.
References:
https://github.com/qpdf/qpdf/issues/243
Discussion:
Created qpdf tracking bugs for this issue:
Affects: epel-6 [bug 1646390]
Affects: fedora-all [bug 1646391]
---
I failed to reproduce this behavior during my testing. However, the real problem here seems to be the use of an arbitrary limit. Finding such limits is always a balancing act.
If you run into this problem in a real world scenario, please comment and we'll investigate and possibly adjust the limit.
2018-10-06
Published