Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerability roundup 53: qpdf-8.2.1: 1 advisory #51101

Closed
1 task done
ckauhaus opened this issue Nov 27, 2018 · 6 comments
Closed
1 task done

Vulnerability roundup 53: qpdf-8.2.1: 1 advisory #51101

ckauhaus opened this issue Nov 27, 2018 · 6 comments

Comments

@ckauhaus
Copy link
Contributor

ckauhaus commented Nov 27, 2018

search, files

Scanned versions: nixos-unstable: 80738ed; nixos-18.09: 5d4a1a3. May contain false positives.

@periklis
Copy link
Contributor

According to the open issue on the project repo it has a cap on 500 levels of recursive calls and then it will abort. Imho we can neglect this issue.

@c0bw3b
Copy link
Contributor

c0bw3b commented Nov 27, 2018

Agreed. CVSSv3 score of 3.3 and worst case scenario is the app hangs for 10min.
It should be safe to just wait for the next release.

@NicoleG25
Copy link

Hi, was this issue ever fixed in the next release and if so what version? thank you ! :)

@c0bw3b
Copy link
Contributor

c0bw3b commented Dec 26, 2019

Hi,
According to upstream issue it was fixed in the 9.x branch, which started on September 1st (v9.0.0).
Current release is v9.1.0.

@NicoleG25
Copy link

Hi,
According to upstream issue it was fixed in the 9.x branch, which started on September 1st (v9.0.0).
Current release is v9.1.0.

Could you possibly point me to the commit fixing the issue?
Thanks !

@ckauhaus
Copy link
Contributor Author

ckauhaus commented Jan 2, 2020

qpdf was last updated to 9.1.0 in 5a0c2f2 (master -> will become 20.03). The update before that was in 12c9003 which unfortunately did not make it into 19.09. HTH

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

4 participants