PT-2025-34570 · Podofo+1 · Podofo+1
Xdcao
·
Published
2025-08-24
·
Updated
2025-09-12
·
CVE-2025-9394
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
PoDoFo version 1.1.0-dev
Description:
A flaw has been identified in the PDF Dictionary Parser component of PoDoFo. The issue resides within the
PdfTokenizer::DetermineDataType function in the file src/podofo/main/PdfTokenizer.cpp. Manipulation of the affected component can lead to a use-after-free condition, potentially allowing for local exploitation. The exploit for this issue has been published.Recommendations:
Apply the patch 22d16cb142f293bf956f66a4d399cdd65576d36c to remediate this issue.
Exploit
Fix
Use After Free
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Podofo