Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:36476
HistoryJul 25, 2022 - 10:24 a.m.

Denial Of Service (DoS)

2022-07-2510:24:10
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9
denial of service
libqpdf
processxrefstream
buffer size
application crash
crafted pdf file
vulnerability

EPSS

0.001

Percentile

31.4%

libqpdf.so is vulnerable to denial of service. The vulnerability exists in the processXRefStream function in qpdf.cc due to improper configuration of buffer size which allows an attacker to cause an application crash via a crafted pdf file.