CVE-2021-36978

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
20/07/2021
Last modified:
15/01/2024

Description

QPDF 9.x through 9.1.1 and 10.x through 10.0.4 has a heap-based buffer overflow in Pl_ASCII85Decoder::write (called from Pl_AES_PDF::flush and Pl_AES_PDF::finish) when a certain downstream write fails.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:qpdf_project:qpdf:*:*:*:*:*:*:*:* 9.0.0 (including) 9.1.1 (including)
cpe:2.3:a:qpdf_project:qpdf:*:*:*:*:*:*:*:* 10.0.0 (including) 10.0.4 (including)