PT-2021-6537 · Podofo+4 · Podofo+4
Mattia Rizzolo
·
Published
2021-04-21
·
Updated
2025-01-20
·
CVE-2020-18971
CVSS v2.0
7.1
High
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
PoDoFo version 0.9.6
Description
The issue is related to a stack-based buffer overflow in the
src/base/PdfDictionary.cpp component, specifically at line 65. This allows attackers to cause a denial of service. The vulnerability is associated with a buffer overflow, which can be exploited by a remote attacker to disrupt service.Recommendations
For PoDoFo version 0.9.6, consider applying a patch or fix that addresses the buffer overflow issue in the
src/base/PdfDictionary.cpp component to prevent denial of service attacks. As a temporary workaround, restrict access to the vulnerable component to minimize the risk of exploitation.Exploit
Fix
DoS
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Debian
Linuxmint
Podofo
Ubuntu