diff options
author | Jay Berkenbilt <ejb@ql.org> | 2020-10-31 18:10:39 +0100 |
---|---|---|
committer | Jay Berkenbilt <ejb@ql.org> | 2020-10-31 18:10:39 +0100 |
commit | 6971f78ff6fb87a7e6da6ee57e8e28ded4fe1a26 (patch) | |
tree | 59d6be7c4bf8aa38971c91f1ef9938e79a64081b /ChangeLog | |
parent | ffe6af6f77036d9c725ce906df6020e4b5cac58d (diff) | |
download | qpdf-6971f78ff6fb87a7e6da6ee57e8e28ded4fe1a26.tar.zst |
Fix stack overflow on direct root (fuzz issue 26761)
Diffstat (limited to 'ChangeLog')
-rw-r--r-- | ChangeLog | 4 |
1 files changed, 4 insertions, 0 deletions
@@ -1,5 +1,9 @@ 2020-10-31 Jay Berkenbilt <ejb@ql.org> + * Don't enter extension initialization in QPDFWriter on a direct + object. Fixes stack overflow in pathological case of /Root being a + direct object (fuzz issue 26761). + * My previous fix to #449 (handling foreign streams with indirect objects in /Filter and/or /DecodeParms) was incorrect and caused other problems. There is a now a correct fix to the original |