Resource exhaustion in QPDF - CVE-2018-9918

 

Resource exhaustion in QPDF - CVE-2018-9918

Published: May 14, 2018


Vulnerability identifier: #VU12631
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-9918
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness exists in the QPDFObjectHandle and QPDF_Dictionary classes due to mishandling certain "expected dictionary key but found non-name object" cases because nesting in direct objects is not restricted. A remote attacker can trigger stack exhaustion and cause the service to crash.

Affected software

QPDF
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Software Development Kit 12
Fedora
cups-filters
qpdf
qpdf-debugsource
qpdf-devel
qpdf-debuginfo
libqpdf18
libqpdf18-debuginfo

How to mitigate CVE-2018-9918

Install update from vendor's website.

cups-filters - update to 1.16.1-5.fc27
qpdf - addressed in versions 5.1.1-6.el6, 7.1.1-5.fc27, 7.1.1-5.fc28
qpdf-debugsource - update to 7.1.1-3.11.1
qpdf-devel - update to 7.1.1-3.11.1
qpdf-debuginfo - update to 7.1.1-3.11.1
qpdf - update to 7.1.1-3.11.1
libqpdf18 - update to 7.1.1-3.11.1
libqpdf18-debuginfo - update to 7.1.1-3.11.1

External References

Related Security Bulletins