Bugzilla – Bug 1214241
VUL-0: CVE-2021-25786: qpdf: heap use after free in Pl_ASCII85Decoder:write()
Last modified: 2023-08-14 09:06:22 UTC
CVE-2021-25786 An issue was discovered in QPDF version 10.0.4, allows remote attackers to execute arbitrary code via crafted .pdf file to Pl_ASCII85Decoder::write parameter in libqpdf. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-25786 https://bugzilla.redhat.com/show_bug.cgi?id=2231536 https://www.cve.org/CVERecord?id=CVE-2021-25786 https://github.com/qpdf/qpdf/issues/492
Already fixed in all codestreams. Closing.