CVE-2022-34503

Source
https://cve.org/CVERecord?id=CVE-2022-34503
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-34503.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-34503
Downstream
Related
Published
2022-07-22T15:15:08.743Z
Modified
2026-02-04T14:23:12.548420Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

QPDF v8.4.2 was discovered to contain a heap buffer overflow via the function QPDF::processXRefStream. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.

References

Affected packages

Git / github.com/qpdf/qpdf

Affected ranges

Type
GIT
Repo
https://github.com/qpdf/qpdf
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

release-qpdf-2.*
release-qpdf-2.0
release-qpdf-2.0.1
release-qpdf-2.0.2
release-qpdf-2.0.3
release-qpdf-2.0.4
release-qpdf-2.0.5
release-qpdf-2.0.6
release-qpdf-2.1
release-qpdf-2.1.1
release-qpdf-2.1.2
release-qpdf-2.1.3
release-qpdf-2.1.4
release-qpdf-2.1.5
release-qpdf-2.1.rc1
release-qpdf-2.2.0
release-qpdf-2.2.1
release-qpdf-2.2.2
release-qpdf-2.2.3
release-qpdf-2.2.4
release-qpdf-2.2.rc1
release-qpdf-2.3.0
release-qpdf-2.3.1
release-qpdf-3.*
release-qpdf-3.0.0
release-qpdf-3.0.1
release-qpdf-3.0.2
release-qpdf-3.0.rc1
release-qpdf-4.*
release-qpdf-4.0.0
release-qpdf-4.0.1
release-qpdf-4.1.0
release-qpdf-4.2.0
release-qpdf-5.*
release-qpdf-5.0.0
release-qpdf-5.0.1
release-qpdf-5.1.0
release-qpdf-5.1.1
release-qpdf-5.1.2
release-qpdf-5.1.3
release-qpdf-5.2.0
release-qpdf-6.*
release-qpdf-6.0.0
release-qpdf-7.*
release-qpdf-7.0.0
release-qpdf-7.0.b1
release-qpdf-7.1.0
release-qpdf-7.1.1
release-qpdf-8.*
release-qpdf-8.0.0
release-qpdf-8.0.1
release-qpdf-8.0.2
release-qpdf-8.0.a1
release-qpdf-8.0.rc1
release-qpdf-8.0.rc2
release-qpdf-8.0.rc3
release-qpdf-8.1.0
release-qpdf-8.2.0
release-qpdf-8.2.1
release-qpdf-8.3.0
release-qpdf-8.4.0
release-qpdf-8.4.1
release-qpdf-8.4.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-34503.json"