CVE-2024-24246
published 2024-02-29CVE-2024-24246: Heap Buffer Overflow vulnerability in qpdf 11.9.0 allows attackers to crash the application via the std::__shared_count() function at /bits/shared_ptr_base.h.
PriorityP418medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.44%
35.4th percentile
Heap Buffer Overflow vulnerability in qpdf 11.9.0 allows attackers to crash the application via the std::__shared_count() function at /bits/shared_ptr_base.h.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | qpdf | < qpdf 11.9.0-1 (forky) | qpdf 11.9.0-1 (forky) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| qpdf_project | qpdf | — | — |
| qpdf_project | qpdf | >= 0 < 11.9.0-1 | 11.9.0-1 |
| qpdf_project | qpdf | >= 0 < 11.9.0-1 | 11.9.0-1 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
QPDF vulnerability
vendor_ubuntu·2024-03-25
CVE-2024-24246 QPDF vulnerability
Title: QPDF vulnerability
Summary: QPDF could be made to crash or run programs if it opened a specially
crafted file.
It was discovered that QPDF incorrectly handled certain memory operations
when decoding JSON files. If a user or automated system were tricked into
processing a specially crafted JSON file, QPDF could be made to crash,
resulting in a denial of service, or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
qpdf: Heap Buffer Overflow vulnerability in qpdf
vendor_redhat·2024-02-29·CVSS 5.5
CVE-2024-24246 [MEDIUM] CWE-126 qpdf: Heap Buffer Overflow vulnerability in qpdf
qpdf: Heap Buffer Overflow vulnerability in qpdf
Heap Buffer Overflow vulnerability in qpdf 11.9.0 allows attackers to crash the application via the std::__shared_count() function at /bits/shared_ptr_base.h.
A flaw was found in qpdf. Processing a specially crafted JSON file using the --json-input command line option may lead to a heap-based buffer over-read, resulting in an application crash.
Statement: The qpdf packages as shipped in Red Hat Enterprise Linux 8 and 9 are not affected by this vulnerability because the support of generating PDFs based on JSON was introduced in a newer version of qpdf.
Package: qpdf (Red Hat Enterprise Linux 7) - Out of support scope
Package: qpdf (Red Hat Enterprise Linux 8) - Not affected
Package: qpdf (Red Hat Enterprise Linux 9) - Not affected
Debian
CVE-2024-24246: qpdf - Heap Buffer Overflow vulnerability in qpdf 11.9.0 allows attackers to crash the ...
vendor_debian·2024·CVSS 5.5
CVE-2024-24246 [MEDIUM] CVE-2024-24246: qpdf - Heap Buffer Overflow vulnerability in qpdf 11.9.0 allows attackers to crash the ...
Heap Buffer Overflow vulnerability in qpdf 11.9.0 allows attackers to crash the application via the std::__shared_count() function at /bits/shared_ptr_base.h.
Scope: local
bookworm: open
bullseye: resolved
forky: resolved (fixed in 11.9.0-1)
sid: resolved (fixed in 11.9.0-1)
trixie: resolved (fixed in 11.9.0-1)
GHSA
GHSA-6733-f273-8q48: Heap Buffer Overflow vulnerability in qpdf 11
ghsa_unreviewed·2024-02-29
CVE-2024-24246 [MEDIUM] CWE-122 GHSA-6733-f273-8q48: Heap Buffer Overflow vulnerability in qpdf 11
Heap Buffer Overflow vulnerability in qpdf 11.9.0 allows attackers to crash the application via the std::__shared_count() function at /bits/shared_ptr_base.h.
OSV
CVE-2024-24246: Heap Buffer Overflow vulnerability in qpdf 11
osv·2024-02-29·CVSS 5.5
CVE-2024-24246 [MEDIUM] CVE-2024-24246: Heap Buffer Overflow vulnerability in qpdf 11
Heap Buffer Overflow vulnerability in qpdf 11.9.0 allows attackers to crash the application via the std::__shared_count() function at /bits/shared_ptr_base.h.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/qpdf/qpdf/issues/1123https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4WLK6ICPJUMOJNHZQWXAA5MPXG5JHZZL/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FX3D3YCNS6CQL3774OFUROLP3EM25ILC/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U3N6TULMEYVCLXO47Y5W4VWCJMSB72CB/https://github.com/qpdf/qpdf/issues/1123https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4WLK6ICPJUMOJNHZQWXAA5MPXG5JHZZL/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FX3D3YCNS6CQL3774OFUROLP3EM25ILC/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/U3N6TULMEYVCLXO47Y5W4VWCJMSB72CB/https://lists.fedoraproject.org/archives/list/[email protected]/message/4WLK6ICPJUMOJNHZQWXAA5MPXG5JHZZL/https://lists.fedoraproject.org/archives/list/[email protected]/message/FX3D3YCNS6CQL3774OFUROLP3EM25ILC/https://lists.fedoraproject.org/archives/list/[email protected]/message/U3N6TULMEYVCLXO47Y5W4VWCJMSB72CB/
2024-02-29
Published