{"id":"CVE-2021-36978","details":"QPDF 9.x through 9.1.1 and 10.x through 10.0.4 has a heap-based buffer overflow in Pl_ASCII85Decoder::write (called from Pl_AES_PDF::flush and Pl_AES_PDF::finish) when a certain downstream write fails.","modified":"2026-05-16T04:03:20.822129700Z","published":"2021-07-20T07:15:08.030Z","related":["SUSE-SU-2022:2669-1","SUSE-SU-2022:2670-1","SUSE-SU-2022:3248-1"],"database_specific":{},"references":[{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2023/08/msg00037.html"},{"type":"ADVISORY","url":"https://github.com/google/oss-fuzz-vulns/blob/main/vulns/qpdf/OSV-2020-2245.yaml"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202401-20"},{"type":"REPORT","url":"https://github.com/qpdf/qpdf/issues/492"},{"type":"FIX","url":"https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=28262"},{"type":"FIX","url":"https://github.com/qpdf/qpdf/commit/dc92574c10f3e2516ec6445b88c5d584f40df4e5"}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"}]}