PT-2023-18484 · Podofo · Podofo
Daisypo
·
Published
2023-04-22
·
Updated
2025-02-04
·
CVE-2023-2241
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PoDoFo version 0.10.0
Description
A critical vulnerability was found in PoDoFo, affecting the function
readXRefStreamEntry of the file PdfXRefStreamParserObject.cpp. The manipulation leads to heap-based buffer overflow. An attack must be approached locally. The exploit has been disclosed to the public and may be used.Recommendations
To fix this issue, it is recommended to apply a patch, specifically the one identified as
535a786f124b739e3c857529cecc29e4eeb79778. As a temporary workaround, consider disabling the readXRefStreamEntry function until a patch is available. Restrict access to the PdfXRefStreamParserObject.cpp file to minimize the risk of exploitation.Exploit
Fix
Buffer Overflow
Heap Based Buffer Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Podofo