PT-2017-18302 · Podofo+2 · Podofo+2

Published

2017-05-01

·

Updated

2024-10-08

·

CVE-2017-8378

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PoDoFo version 0.9.5
Description The issue is related to a heap-based buffer overflow in the PdfParser::ReadObjects function, which can be exploited by remote attackers to cause a denial of service, resulting in an application crash, or possibly have other unspecified impacts. This is achieved through vectors related to m offsets.size.
Recommendations For PoDoFo version 0.9.5, consider applying a patch or fix that addresses the heap-based buffer overflow in the PdfParser::ReadObjects function to prevent potential denial of service or other impacts. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Buffer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2018-2273
CVE-2017-8378
OPENSUSE-SU-2024_3550-1
SUSE-SU-2024:3541-1
SUSE-SU-2024:3550-1

Affected Products

Alt Linux
Podofo
Suse