PT-2018-12438 · Podofo · Podofo

Published

2018-09-13

·

Updated

2025-09-04

·

CVE-2018-14320

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions PoDoFo (affected versions not specified)
Description This issue allows remote attackers to disclose sensitive information on vulnerable installations. It requires user interaction, such as visiting a malicious page or opening a malicious file. The flaw exists within PdfEncoding::ParseToUnicode due to the lack of proper validation of user-supplied data, leading to a memory corruption condition. This can be leveraged to execute arbitrary code in the context of the current process when combined with other vulnerabilities.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-14320
MGASA-2019-0044
OPENSUSE-SU-2024:11178-1
OPENSUSE-SU-2025:15521-1
ZDI-18-1046

Affected Products

Podofo