Files
CVEs-PoC/2017/CVE-2017-11624.md
2025-09-29 21:09:30 +02:00

817 B

CVE-2017-11624

Description

A stack-consumption vulnerability was found in libqpdf in QPDF 6.0.0, which allows attackers to cause a denial of service via a crafted file, related to the QPDFTokenizer::resolveLiteral function in QPDFTokenizer.cc after two consecutive calls to QPDFObjectHandle::parseInternal, aka an "infinite loop."

POC

Reference

Github

No PoCs found on GitHub currently.