Red Hat Bugzilla – Bug 1545278
CVE-2017-18184 qpdf: out-of-bounds read in iterate_rc4 in QPDF_encryption.cc
Last modified: 2018-03-29 18:05:16 EDT
A flaw was found in QPDF before 7.1.1 There is a stack-based out-of-bounds read in the function iterate_rc4 in QPDF_encryption.cc. This allows an attacker to cause a denial of service via a crafted file. External References: https://github.com/qpdf/qpdf/issues/147 Upstream Patch: https://github.com/qpdf/qpdf/commit/dea704f0ab7f625e1e7b3f9a1110b45b63157317