CVE-2018-9918 PUBLISHED

libqpdf.a in QPDF through 8.0.2 mishandles certain "expected dictionary key but found non-name object" cases, allowing remote attackers to cause a denial of service (stack exhaustion), related to the QPDFObjectHandle and QPDF_Dictionary classes, because nesting in direct objects is not restricted.

EPSS 0.86% · 74.9th percentile

Risk Scores

EPSS Score
0.86%
74.9th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSqpdf6.0.0-2, 0, 5.1.3-2
Ubuntu:14.04:LTSqpdf0, 4.2.0-2, 5.0.1-1

Timeline

References

Open in Interactive Console →