{"id":"CVE-2017-12595","details":"The tokenizer in QPDF 6.0.0 and 7.0.b1 is recursive for arrays and dictionaries, which allows remote attackers to cause a denial of service (stack consumption and segmentation fault) or possibly have unspecified other impact via a PDF document with a deep data structure, as demonstrated by a crash in QPDFObjectHandle::parseInternal in libqpdf/QPDFObjectHandle.cc.","modified":"2026-05-07T19:41:47.735436Z","published":"2017-08-27T15:29:00.200Z","related":["SUSE-SU-2018:3066-1","SUSE-SU-2018:3066-2","openSUSE-SU-2024:11289-1"],"references":[{"type":"WEB","url":"https://usn.ubuntu.com/3638-1/"},{"type":"FIX","url":"https://github.com/qpdf/qpdf/commit/ad527a64f93dca12f6aabab2ca99ae5eb352ab4b"},{"type":"FIX","url":"https://github.com/qpdf/qpdf/issues/146"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/qpdf/qpdf","events":[{"introduced":"0"},{"last_affected":"46eb1047df9b4998d53c5182ddc362fb4c5c62a7"},{"last_affected":"556e0bdd2bdb9c109f3c84775e8419e0e5b58277"}],"database_specific":{"cpe":["cpe:2.3:a:qpdf_project:qpdf:6.0.0:*:*:*:*:*:*:*","cpe:2.3:a:qpdf_project:qpdf:7.0.b1:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"last_affected":"6.0.0"},{"last_affected":"7.0.b1"}],"source":"CPE_FIELD"}}],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2017-12595.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}