QID 671118
Date Published: 2021-11-29
QID 671118: EulerOS Security Update for qpdf (EulerOS-SA-2019-2655)
Qpdf is a command-line program that does structural, content-preserving transformations on pdf files.
It could have been called something like pdf-to-pdf.
It includes support for merging and splitting pdfs and to manipulate the list of pages in a pdf file.
It is not a pdf viewer or a program capable of converting pdf into other formats.
Security fix(es): an issue was discovered in qpdf before 7.0.0.
Endless recursion causes stack exhaustion in qpdftokenizer::resolveliteral() in qpdftokenizer.cc, related to the qpdf::resolve function in qpdf.cc.(cve-2015-9252) an issue was discovered in qpdf before 7.0.0.
There is an infinite loop due to looping xref tables in qpdf.cc.(cve-2017-18186)
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
An arbitrary attacker may exploit this vulnerability to compromise the system.
CVEs related to QID 671118
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| EulerOS-SA-2019-2655 | EulerOS V2.0SP3 |
|