PT-2019-12012 · Podofo+5 · Podofo+5

Tao Lv

·

Publicado

2019-04-03

·

Atualizado

2025-09-04

·

CVE-2019-10723

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions PoDoFo version 0.9.6
Description An issue was discovered in the PdfPagesTreeCache class where there is an attempted excessive memory allocation due to the lack of validation of the nInitialSize variable.
Recommendations For PoDoFo version 0.9.6, consider validating the nInitialSize variable in the PdfPagesTreeCache class to prevent excessive memory allocation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Allocation of Resources Without Limits

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2021-1684
ALT-PU-2022-3234
CVE-2019-10723
OPENSUSE-SU-2024:11855-1
OPENSUSE-SU-2024_2137-1
OPENSUSE-SU-2025:15521-1
SUSE-SU-2024:2137-1
SUSE-SU-2024:3541-1
USN-7217-1

Produtos afetados

Alt Linux
Debian
Linuxmint
Podofo
Suse
Ubuntu