Bugzilla – Bug 1221043
VUL-0: CVE-2024-24246: qpdf: heap out of bounds read in the JSON reactor
Last modified: 2024-03-06 10:01:26 UTC
Heap Buffer Overflow vulnerability in qpdf 11.9.0 allows attackers to crash the application via the std::__shared_count() function at /bits/shared_ptr_base.h. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-24246 https://www.cve.org/CVERecord?id=CVE-2024-24246 https://github.com/qpdf/qpdf/issues/1123 https://bugzilla.redhat.com/show_bug.cgi?id=2267204
qpdf in SUSE:SLE-12:Update and SUSE:SLE-15:Update don't seem to have JSON support. The versions in SUSE:SLE-15-SP2:Update and SUSE:SLE-15-SP3:Update have completely different JSON code. openSUSE:Factory is already fixed. Closing.