Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.10.2017.0237
Category:Mageia Linux Local Security Checks
Title:Mageia: Security Advisory (MGASA-2017-0237)
Summary:The remote host is missing an update for the 'cups-filters, qpdf' package(s) announced via the MGASA-2017-0237 advisory.
Description:Summary:
The remote host is missing an update for the 'cups-filters, qpdf' package(s) announced via the MGASA-2017-0237 advisory.

Vulnerability Insight:
This snapshot of the upstream development branch (6.0) of qpdf fixes
several infinite loop vulnerabilities: CVE-2017-9208, CVE-2017-9209,
CVE-2017-9210, CVE-2017-11624, CVE-2017-11625, CVE-2017-11626,
CVE-2017-11627.

For Mageia 5, the cups-filters package was also rebuilt against this
new major version of qpdf.

Affected Software/OS:
'cups-filters, qpdf' package(s) on Mageia 5, Mageia 6.

Solution:
Please install the updated package(s).

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:N/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2017-11624
http://somevulnsofadlab.blogspot.jp/2017/07/qpdfan-infinite-loop-in-libqpdf.html
https://github.com/qpdf/qpdf/issues/117
https://usn.ubuntu.com/3638-1/
Common Vulnerability Exposure (CVE) ID: CVE-2017-11625
http://somevulnsofadlab.blogspot.jp/2017/07/qpdfan-infinite-loop-in-libqpdf_26.html
https://github.com/qpdf/qpdf/issues/120
Common Vulnerability Exposure (CVE) ID: CVE-2017-11626
http://somevulnsofadlab.blogspot.jp/2017/07/qpdfan-infinite-loop-in-libqpdf_65.html
https://github.com/qpdf/qpdf/issues/119
Common Vulnerability Exposure (CVE) ID: CVE-2017-11627
http://somevulnsofadlab.blogspot.jp/2017/07/qpdfan-infinite-loop-in-libqpdf_21.html
https://github.com/qpdf/qpdf/issues/118
Common Vulnerability Exposure (CVE) ID: CVE-2017-9208
https://blogs.gentoo.org/ago/2017/05/21/qpdf-three-infinite-loop-in-libqpdf/
Common Vulnerability Exposure (CVE) ID: CVE-2017-9209
Common Vulnerability Exposure (CVE) ID: CVE-2017-9210
CopyrightCopyright (C) 2022 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.