PT-2025-34570 · Podofo+1 · Podofo+1

Xdcao

·

Published

2025-08-24

·

Updated

2025-09-12

·

CVE-2025-9394

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: PoDoFo version 1.1.0-dev
Description: A flaw has been identified in the PDF Dictionary Parser component of PoDoFo. The issue resides within the PdfTokenizer::DetermineDataType function in the file src/podofo/main/PdfTokenizer.cpp. Manipulation of the affected component can lead to a use-after-free condition, potentially allowing for local exploitation. The exploit for this issue has been published.
Recommendations: Apply the patch 22d16cb142f293bf956f66a4d399cdd65576d36c to remediate this issue.

Exploit

Fix

Use After Free

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2025-9394

Affected Products

Debian
Podofo