Menu

qpdf 5.0.1

I have released qpdf 5.0.1. This version contains several security hardening changes thanks to a review from Florian Weimer of the Red Hat Product Security Team. An analysis of the issues suggests that there are likely some ways to make older versions of qpdf crash on certain malformed files but there don't seem to be any opportunities for buffer overruns or other ways to inject malicious code. No CVEs are being issued based on the changes. Still, it is recommended to upgrade to 5.0.1. For details, see the revision history or the ChangeLog.

Posted by Jay Berkenbilt 2013-10-18