Loading
Generated remediation guidance and an executive summary. No account required.
An issue was discovered in QPDF version 10.0.4, allows remote attackers to execute arbitrary code via crafted .pdf file to Pl_ASCII85Decoder::write parameter in libqpdf.
Use CWE-416, Qpdf Project vendor hub and Qpdf product page to widen CVE-2021-25786 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2018-9918, CVE-2017-12595 and CVE-2022-34503 for nearby disclosures in the same product family.