QPDF 9.x through 9.1.1 and 10.x through 10.0.4 has a heap-based buffer overflow in PlASCII85Decoder::write (called from PlAESPDF::flush and PlAES_PDF::finish) when a certain downstream write fails.
{ "urgency": "not yet assigned" }