Lucene search

K
redhatcveRedhat.comRH:CVE-2022-34503
HistoryJul 27, 2022 - 4:55 a.m.

CVE-2022-34503

2022-07-2704:55:00
redhat.com
access.redhat.com
27
cve-2022-34503
qpdf
buffer overflow
denial of service
pdf file

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

31.4%

A heap buffer overflow vulnerability was discovered in qpdf via the QPDF::processXRefStream() function. This flaw allows an attacker to cause a denial of service (DoS) via a crafted PDF file.

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

31.4%