PT-2019-12012 · Podofo+5 · Podofo+5

Tao Lv

·

Published

2019-04-03

·

Updated

2025-09-04

·

CVE-2019-10723

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions PoDoFo version 0.9.6
Description An issue was discovered in the PdfPagesTreeCache class where there is an attempted excessive memory allocation due to the lack of validation of the nInitialSize variable.
Recommendations For PoDoFo version 0.9.6, consider validating the nInitialSize variable in the PdfPagesTreeCache class to prevent excessive memory allocation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1684
ALT-PU-2022-3234
CVE-2019-10723
OPENSUSE-SU-2024:11855-1
OPENSUSE-SU-2024_2137-1
OPENSUSE-SU-2025:15521-1
SUSE-SU-2024:2137-1
SUSE-SU-2024:3541-1
USN-7217-1

Affected Products

Alt Linux
Debian
Linuxmint
Podofo
Suse
Ubuntu