CVE-2021-25786Use After Free in Project Qpdf

CWE-416Use After Free6 documents6 sources
Severity
5.3MEDIUMNVD
EPSS
0.3%
top 46.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 11

Description

An issue was discovered in QPDF version 10.0.4, allows remote attackers to execute arbitrary code via crafted .pdf file to Pl_ASCII85Decoder::write parameter in libqpdf.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:LExploitability: 1.8 | Impact: 3.4

Affected Packages2 packages

Debianqpdf_project/qpdf< 10.1.0-1+3
NVDqpdf_project/qpdf10.0.4

Patches

🔴Vulnerability Details

3
OSV
CVE-2021-25786: An issue was discovered in QPDF version 102023-08-11
GHSA
GHSA-f3pg-6m52-2j62: An issue was discovered in QPDF version 102023-08-11
CVEList
CVE-2021-25786: An issue was discovered in QPDF version 102023-08-11

📋Vendor Advisories

2
Red Hat
qpdf: Heap use after free in Pl_ASCII85Decoder::write2023-08-11
Debian
CVE-2021-25786: qpdf - An issue was discovered in QPDF version 10.0.4, allows remote attackers to execu...2021
CVE-2021-25786 — Use After Free in Qpdf Project Qpdf | cvebase