PT-2023-18484 · Podofo · Podofo
Daisypo
·
Publicado
2023-04-22
·
Atualizado
2025-02-04
·
CVE-2023-2241
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PoDoFo version 0.10.0
Description
A critical vulnerability was found in PoDoFo, affecting the function
readXRefStreamEntry of the file PdfXRefStreamParserObject.cpp. The manipulation leads to heap-based buffer overflow. An attack must be approached locally. The exploit has been disclosed to the public and may be used.Recommendations
To fix this issue, it is recommended to apply a patch, specifically the one identified as
535a786f124b739e3c857529cecc29e4eeb79778. As a temporary workaround, consider disabling the readXRefStreamEntry function until a patch is available. Restrict access to the PdfXRefStreamParserObject.cpp file to minimize the risk of exploitation.Exploit
Correção
Buffer Overflow
Heap Based Buffer Overflow
Memory Corruption
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Podofo