An issue was discovered in QPDF version 10.0.4, allows remote attackers to execute arbitrary code via crafted .pdf file to Pl_ASCII85Decoder::write parameter in libqpdf.
{
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
"binaries": [
{
"binary_name": "libqpdf-dev",
"binary_version": "8.0.2-3~16.04.1+esm1"
},
{
"binary_name": "libqpdf21",
"binary_version": "8.0.2-3~16.04.1+esm1"
},
{
"binary_name": "qpdf",
"binary_version": "8.0.2-3~16.04.1+esm1"
}
]
}