PT-2023-18484 · Podofo · Podofo

Daisypo

·

Publicado

2023-04-22

·

Atualizado

2025-02-04

·

CVE-2023-2241

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PoDoFo version 0.10.0
Description A critical vulnerability was found in PoDoFo, affecting the function readXRefStreamEntry of the file PdfXRefStreamParserObject.cpp. The manipulation leads to heap-based buffer overflow. An attack must be approached locally. The exploit has been disclosed to the public and may be used.
Recommendations To fix this issue, it is recommended to apply a patch, specifically the one identified as 535a786f124b739e3c857529cecc29e4eeb79778. As a temporary workaround, consider disabling the readXRefStreamEntry function until a patch is available. Restrict access to the PdfXRefStreamParserObject.cpp file to minimize the risk of exploitation.

Exploit

Correção

Buffer Overflow

Heap Based Buffer Overflow

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-2241

Produtos afetados

Podofo