PT-2019-12012 · Podofo+5 · Podofo+5
Tao Lv
·
Published
2019-04-03
·
Updated
2025-09-04
·
CVE-2019-10723
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
PoDoFo version 0.9.6
Description
An issue was discovered in the PdfPagesTreeCache class where there is an attempted excessive memory allocation due to the lack of validation of the
nInitialSize variable.Recommendations
For PoDoFo version 0.9.6, consider validating the
nInitialSize variable in the PdfPagesTreeCache class to prevent excessive memory allocation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Debian
Linuxmint
Podofo
Suse
Ubuntu