CVE-2021-36978
published 2021-07-20CVE-2021-36978: QPDF 9.x through 9.1.1 and 10.x through 10.0.4 has a heap-based buffer overflow in Pl_ASCII85Decoder::write (called from Pl_AES_PDF::flush and…
PriorityP423medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
1.27%
66.6th percentile
QPDF 9.x through 9.1.1 and 10.x through 10.0.4 has a heap-based buffer overflow in Pl_ASCII85Decoder::write (called from Pl_AES_PDF::flush and Pl_AES_PDF::finish) when a certain downstream write fails.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | qpdf | < qpdf 10.1.0-1 (bookworm) | qpdf 10.1.0-1 (bookworm) |
| qpdf_project | qpdf | >= 0 < 10.1.0-1 | 10.1.0-1 |
| qpdf_project | qpdf | >= 0 < 10.1.0-1 | 10.1.0-1 |
| qpdf_project | qpdf | >= 0 < 10.1.0-1 | 10.1.0-1 |
| qpdf_project | qpdf | >= 0 < 10.1.0-1 | 10.1.0-1 |
| qpdf_project | qpdf | >= 0 < 8.0.2-3ubuntu0.1 | 8.0.2-3ubuntu0.1 |
| qpdf_project | qpdf | >= 0 < 9.1.1-1ubuntu0.1 | 9.1.1-1ubuntu0.1 |
| qpdf_project | qpdf | >= 0 < 8.0.2-3~16.04.1+esm1 | 8.0.2-3~16.04.1+esm1 |
| qpdf_project | qpdf | 10.0.0 – 10.0.4 | — |
| qpdf_project | qpdf | 9.0.0 – 9.1.1 | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
QPDF vulnerabilities
vendor_ubuntu·2021-08-02·CVSS 3.3
CVE-2021-36978 [LOW] QPDF vulnerabilities
Title: QPDF vulnerabilities
Summary: Several security issues were fixed in QPDF.
USN-5026-1 fixed several vulnerabilities in QPDF. This update provides
the corresponding update for Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that QPDF incorrectly handled certain malformed PDF
files. A remote attacker could use this issue to cause QPDF to consume
resources, resulting in a denial of service. (CVE-2018-18020)
It was discovered that QPDF incorrectly handled certain malformed PDF
files. A remote attacker could use this issue to cause QPDF to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2021-36978)
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
QPDF vulnerabilities
vendor_ubuntu·2021-07-29·CVSS 3.3
CVE-2018-18020 [LOW] QPDF vulnerabilities
Title: QPDF vulnerabilities
Summary: Several security issues were fixed in QPDF.
It was discovered that QPDF incorrectly handled certain malformed PDF
files. A remote attacker could use this issue to cause QPDF to consume
resources, resulting in a denial of service. This issue only affected
Ubuntu 18.04 LTS. (CVE-2018-18020)
It was discovered that QPDF incorrectly handled certain malformed PDF
files. A remote attacker could use this issue to cause QPDF to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2021-36978)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
qpdf: heap-based buffer overflow in Pl_ASCII85Decoder::write() when a certain downstream write fails
vendor_redhat·2021-01-04·CVSS 5.5
CVE-2021-36978 [MEDIUM] CWE-119 qpdf: heap-based buffer overflow in Pl_ASCII85Decoder::write() when a certain downstream write fails
qpdf: heap-based buffer overflow in Pl_ASCII85Decoder::write() when a certain downstream write fails
QPDF 9.x through 9.1.1 and 10.x through 10.0.4 has a heap-based buffer overflow in Pl_ASCII85Decoder::write (called from Pl_AES_PDF::flush and Pl_AES_PDF::finish) when a certain downstream write fails.
Package: qpdf (Red Hat Enterprise Linux 7) - Out of support scope
Package: qpdf (Red Hat Enterprise Linux 8) - Will not fix
Package: qpdf (Red Hat Enterprise Linux 9) - Not affected
Debian
CVE-2021-36978: qpdf - QPDF 9.x through 9.1.1 and 10.x through 10.0.4 has a heap-based buffer overflow ...
vendor_debian·2021·CVSS 5.5
CVE-2021-36978 [MEDIUM] CVE-2021-36978: qpdf - QPDF 9.x through 9.1.1 and 10.x through 10.0.4 has a heap-based buffer overflow ...
QPDF 9.x through 9.1.1 and 10.x through 10.0.4 has a heap-based buffer overflow in Pl_ASCII85Decoder::write (called from Pl_AES_PDF::flush and Pl_AES_PDF::finish) when a certain downstream write fails.
Scope: local
bookworm: resolved (fixed in 10.1.0-1)
bullseye: resolved (fixed in 10.1.0-1)
forky: resolved (fixed in 10.1.0-1)
sid: resolved (fixed in 10.1.0-1)
trixie: resolved (fixed in 10.1.0-1)
GHSA
GHSA-vgrr-57vg-f5rq: QPDF 9
ghsa_unreviewed·2022-05-24
CVE-2021-36978 [MEDIUM] CWE-787 GHSA-vgrr-57vg-f5rq: QPDF 9
QPDF 9.x through 9.1.1 and 10.x through 10.0.4 has a heap-based buffer overflow in Pl_ASCII85Decoder::write (called from Pl_AES_PDF::flush and Pl_AES_PDF::finish) when a certain downstream write fails.
OSV
qpdf vulnerabilities
osv·2021-08-02·CVSS 3.3
CVE-2018-18020 [LOW] qpdf vulnerabilities
qpdf vulnerabilities
USN-5026-1 fixed several vulnerabilities in QPDF. This update provides
the corresponding update for Ubuntu 16.04 ESM.
Original advisory details:
It was discovered that QPDF incorrectly handled certain malformed PDF
files. A remote attacker could use this issue to cause QPDF to consume
resources, resulting in a denial of service. (CVE-2018-18020)
It was discovered that QPDF incorrectly handled certain malformed PDF
files. A remote attacker could use this issue to cause QPDF to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2021-36978)
OSV
qpdf vulnerabilities
osv·2021-07-29·CVSS 3.3
CVE-2018-18020 [LOW] qpdf vulnerabilities
qpdf vulnerabilities
It was discovered that QPDF incorrectly handled certain malformed PDF
files. A remote attacker could use this issue to cause QPDF to consume
resources, resulting in a denial of service. This issue only affected
Ubuntu 18.04 LTS. (CVE-2018-18020)
It was discovered that QPDF incorrectly handled certain malformed PDF
files. A remote attacker could use this issue to cause QPDF to crash,
resulting in a denial of service, or possibly execute arbitrary code.
(CVE-2021-36978)
OSV
CVE-2021-36978: QPDF 9
osv·2021-07-20·CVSS 5.5
CVE-2021-36978 [MEDIUM] CVE-2021-36978: QPDF 9
QPDF 9.x through 9.1.1 and 10.x through 10.0.4 has a heap-based buffer overflow in Pl_ASCII85Decoder::write (called from Pl_AES_PDF::flush and Pl_AES_PDF::finish) when a certain downstream write fails.
No detection rules found.
Nuclei
WordPress JH 404 Logger <=1.1 - Cross-Site Scripting
nuclei·CVSS 5.4
CVE-2021-24176 [MEDIUM] WordPress JH 404 Logger <=1.1 - Cross-Site Scripting
WordPress JH 404 Logger =1.2) which addresses the XSS vulnerability.
reference:
- https://wpscan.com/vulnerability/705bcd6e-6817-4f89-be37-901a767b0585
- https://wordpress.org/plugins/jh-404-logger/
- https://ganofins.com/blog/my-first-cve-2021-24176/
- https://nvd.nist.gov/vuln/detail/CVE-2021-24176
- https://github.com/ARPSyndicate/cvemon
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
cvss-score: 5.4
cve-id: CVE-2021-24176
cwe-id: CWE-79
epss-score: 0.36978
epss-percentile: 0.97154
cpe: cpe:2.3:a:jh_404_logger_project:jh_404_logger:*:*:*:*:*:wordpress:*:*
metadata:
max-request: 1
vendor: jh_404_logger_project
product: jh_404_logger
framework: wordpress
tags: cve2021,cve,wordpress,wp-plugin,xss,wpscan,jh_404_logger_project,vuln
http:
- method: GET
path:
- "{{B
No writeups or analysis indexed.
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=28262https://github.com/google/oss-fuzz-vulns/blob/main/vulns/qpdf/OSV-2020-2245.yamlhttps://github.com/qpdf/qpdf/commit/dc92574c10f3e2516ec6445b88c5d584f40df4e5https://github.com/qpdf/qpdf/issues/492https://lists.debian.org/debian-lts-announce/2023/08/msg00037.htmlhttps://security.gentoo.org/glsa/202401-20https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=28262https://github.com/google/oss-fuzz-vulns/blob/main/vulns/qpdf/OSV-2020-2245.yamlhttps://github.com/qpdf/qpdf/commit/dc92574c10f3e2516ec6445b88c5d584f40df4e5https://github.com/qpdf/qpdf/issues/492https://lists.debian.org/debian-lts-announce/2023/08/msg00037.htmlhttps://security.gentoo.org/glsa/202401-20
2021-07-20
Published