CVE-2017-12595
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The tokenizer in QPDF 6.0.0 and 7.0.b1 is recursive for arrays and dictionaries, which allows remote attackers to cause a denial of service (stack consumption and segmentation fault) or possibly have unspecified other impact via a PDF document with a deep data structure, as demonstrated by a crash in QPDFObjectHandle::parseInternal in libqpdf/QPDFObjectHandle.cc.
El tokenizador en QPDF 6.0.0 y 7.0.b1 es recursivo para los arrays y diccionarios, lo que permite a los atacantes remotos provocar una denegación de servicio (consumo de pila y error de segmentación) o causar otro impacto no especificado mediante un documento PDF con una estructura de datos profunda, tal y como se puede comprobar con un fallo en QPDFObjectHandle::parseInternal en libqpdf/QPDFObjectHandle.cc.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-08-06 CVE Reserved
- 2017-08-27 CVE Published
- 2024-01-12 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/qpdf/qpdf/commit/ad527a64f93dca12f6aabab2ca99ae5eb352ab4b | 2018-05-08 | |
https://github.com/qpdf/qpdf/issues/146 | 2018-05-08 |
URL | Date | SRC |
---|---|---|
https://usn.ubuntu.com/3638-1 | 2018-05-08 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Qpdf Project Search vendor "Qpdf Project" | Qpdf Search vendor "Qpdf Project" for product "Qpdf" | 6.0.0 Search vendor "Qpdf Project" for product "Qpdf" and version "6.0.0" | - |
Affected
| ||||||
Qpdf Project Search vendor "Qpdf Project" | Qpdf Search vendor "Qpdf Project" for product "Qpdf" | 7.0.b1 Search vendor "Qpdf Project" for product "Qpdf" and version "7.0.b1" | - |
Affected
|