rpm package
suse/cups-filters&distro=SUSE Linux Enterprise Server for SAP Applications 12 SP2
pkg:rpm/suse/cups-filters&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2
Vulnerabilities (8)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2017-12595 | Hig | 7.8 | < 1.0.58-15.2.1 | 1.0.58-15.2.1 | Aug 27, 2017 | The tokenizer in QPDF 6.0.0 and 7.0.b1 is recursive for arrays and dictionaries, which allows remote attackers to cause a denial of service (stack consumption and segmentation fault) or possibly have unspecified other impact via a PDF document with a deep data structure, as demon | |
| CVE-2017-11627 | Med | 5.5 | < 1.0.58-15.2.1 | 1.0.58-15.2.1 | Jul 25, 2017 | A stack-consumption vulnerability was found in libqpdf in QPDF 6.0.0, which allows attackers to cause a denial of service via a crafted file, related to the PointerHolder function in PointerHolder.hh, aka an "infinite loop." | |
| CVE-2017-11626 | Med | 5.5 | < 1.0.58-15.2.1 | 1.0.58-15.2.1 | Jul 25, 2017 | A stack-consumption vulnerability was found in libqpdf in QPDF 6.0.0, which allows attackers to cause a denial of service via a crafted file, related to the QPDFTokenizer::resolveLiteral function in QPDFTokenizer.cc after four consecutive calls to QPDFObjectHandle::parseInternal, | |
| CVE-2017-11625 | Med | 5.5 | < 1.0.58-15.2.1 | 1.0.58-15.2.1 | Jul 25, 2017 | A stack-consumption vulnerability was found in libqpdf in QPDF 6.0.0, which allows attackers to cause a denial of service via a crafted file, related to the QPDF::resolveObjectsInStream function in QPDF.cc, aka an "infinite loop." | |
| CVE-2017-11624 | Med | 5.5 | < 1.0.58-15.2.1 | 1.0.58-15.2.1 | Jul 25, 2017 | A stack-consumption vulnerability was found in libqpdf in QPDF 6.0.0, which allows attackers to cause a denial of service via a crafted file, related to the QPDFTokenizer::resolveLiteral function in QPDFTokenizer.cc after two consecutive calls to QPDFObjectHandle::parseInternal, | |
| CVE-2017-9210 | Med | 5.5 | < 1.0.58-15.2.1 | 1.0.58-15.2.1 | May 23, 2017 | libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) via a crafted PDF document, related to unparse functions, aka qpdf-infiniteloop3. | |
| CVE-2017-9209 | Med | 5.5 | < 1.0.58-15.2.1 | 1.0.58-15.2.1 | May 23, 2017 | libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) via a crafted PDF document, related to QPDFObjectHandle::parseInternal, aka qpdf-infiniteloop2. | |
| CVE-2017-9208 | Med | 5.5 | < 1.0.58-15.2.1 | 1.0.58-15.2.1 | May 23, 2017 | libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) via a crafted PDF document, related to releaseResolved functions, aka qpdf-infiniteloop1. |
- affected < 1.0.58-15.2.1fixed 1.0.58-15.2.1
The tokenizer in QPDF 6.0.0 and 7.0.b1 is recursive for arrays and dictionaries, which allows remote attackers to cause a denial of service (stack consumption and segmentation fault) or possibly have unspecified other impact via a PDF document with a deep data structure, as demon
- affected < 1.0.58-15.2.1fixed 1.0.58-15.2.1
A stack-consumption vulnerability was found in libqpdf in QPDF 6.0.0, which allows attackers to cause a denial of service via a crafted file, related to the PointerHolder function in PointerHolder.hh, aka an "infinite loop."
- affected < 1.0.58-15.2.1fixed 1.0.58-15.2.1
A stack-consumption vulnerability was found in libqpdf in QPDF 6.0.0, which allows attackers to cause a denial of service via a crafted file, related to the QPDFTokenizer::resolveLiteral function in QPDFTokenizer.cc after four consecutive calls to QPDFObjectHandle::parseInternal,
- affected < 1.0.58-15.2.1fixed 1.0.58-15.2.1
A stack-consumption vulnerability was found in libqpdf in QPDF 6.0.0, which allows attackers to cause a denial of service via a crafted file, related to the QPDF::resolveObjectsInStream function in QPDF.cc, aka an "infinite loop."
- affected < 1.0.58-15.2.1fixed 1.0.58-15.2.1
A stack-consumption vulnerability was found in libqpdf in QPDF 6.0.0, which allows attackers to cause a denial of service via a crafted file, related to the QPDFTokenizer::resolveLiteral function in QPDFTokenizer.cc after two consecutive calls to QPDFObjectHandle::parseInternal,
- affected < 1.0.58-15.2.1fixed 1.0.58-15.2.1
libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) via a crafted PDF document, related to unparse functions, aka qpdf-infiniteloop3.
- affected < 1.0.58-15.2.1fixed 1.0.58-15.2.1
libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) via a crafted PDF document, related to QPDFObjectHandle::parseInternal, aka qpdf-infiniteloop2.
- affected < 1.0.58-15.2.1fixed 1.0.58-15.2.1
libqpdf.a in QPDF 6.0.0 allows remote attackers to cause a denial of service (infinite recursion and stack consumption) via a crafted PDF document, related to releaseResolved functions, aka qpdf-infiniteloop1.