Bug 56507 - qpdf: Multiple issues (5.0)
Summary: qpdf: Multiple issues (5.0)
Status: CLOSED FIXED
Alias: None
Product: UCS
Classification: Unclassified
Component: Security updates
Version: UCS 5.0
Hardware: All Linux
: P3 normal
Target Milestone: UCS 5.0-4-errata
Assignee: Quality Assurance
QA Contact: Philipp Hahn
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2023-08-30 17:57 CEST by Quality Assurance
Modified: 2023-09-06 16:45 CEST (History)
1 user (show)

See Also:
What kind of report is it?: Security Issue
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional):
Customer ID:
Max CVSS v3 score: 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Quality Assurance univentionstaff 2023-08-30 17:57:53 CEST
New Debian qpdf 8.4.0-2+deb10u1 fixes:
This update addresses the following issues:
8.4.0-2+deb10u1 (Mon, 28 Aug 2023 19:03:02 +0200)
* Non-maintainer upload by the LTS Team.
* CVE-2018-18020 crafted files could create recursive calls for a long time,  which allows remote attackers to cause a denial of service
* CVE-2021-25786 crafted files allow remote attackers to execute arbitrary  code
* CVE-2021-36978 a heap-based buffer overflow might occur when a certain  downstream write fails
Comment 1 Quality Assurance univentionstaff 2023-08-30 18:00:18 CEST
--- mirror/ftp/pool/main/q/qpdf/qpdf_8.4.0-2.dsc
+++ apt/ucs_5.0-0-errata5.0-4/source/qpdf_8.4.0-2+deb10u1.dsc
@@ -1,3 +1,15 @@
+8.4.0-2+deb10u1 [Mon, 28 Aug 2023 19:03:02 +0200] Thorsten Alteholz <debian@alteholz.de>:
+
+  * Non-maintainer upload by the LTS Team.
+  * CVE-2018-18020
+    crafted files could create recursive calls for a long time, which
+    allows remote attackers to cause a denial of service
+  * CVE-2021-25786
+    crafted files allow remote attackers to execute arbitrary code
+  * CVE-2021-36978
+    a heap-based buffer overflow might occur when a certain
+    downstream write fails
+
 8.4.0-2 [Fri, 08 Feb 2019 17:43:33 -0500] Jay Berkenbilt <qjb@debian.org>:
 
   * Stop having library packages recommend binary packages. I'm not sure

<http://piuparts.knut.univention.de/5.0-4/#4078991270666018380>
Comment 2 Philipp Hahn univentionstaff 2023-08-30 18:44:14 CEST
OK: bug
OK: yaml
OK: announce_errata
OK: patch
OK: piuparts

[5.0-4] 64cf0b7436 Bug #56507: qpdf 8.4.0-2+deb10u1
 doc/errata/staging/qpdf.yaml | 8 +++-----
 1 file changed, 3 insertions(+), 5 deletions(-)

[5.0-4] e121543854 Bug #56507: qpdf 8.4.0-2+deb10u1
 doc/errata/staging/qpdf.yaml | 21 +++++++++++++++++++++
 1 file changed, 21 insertions(+)