Loading
Generated remediation guidance and an executive summary. No account required.
A stack-consumption vulnerability was found in libqpdf in QPDF 6.0.0, which allows attackers to cause a denial of service via a crafted file, related to the QPDF::resolveObjectsInStream function in QPDF.cc, aka an "infinite loop."
Use CWE-835, Qpdf Project vendor hub and Qpdf product page to widen CVE-2017-11625 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2018-9918, CVE-2017-12595 and CVE-2022-34503 for nearby disclosures in the same product family.