PT-2025-40287 · Podofo+1 · Podofo+1

Shadowbyte1

·

Published

2025-10-01

·

Updated

2025-10-27

·

CVE-2025-46205

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions podofo versions 0.10.0 through 0.10.5
Description A heap-use-after-free issue exists in the PdfTokenizer::ReadDictionary function. This allows attackers to potentially cause a Denial of Service (DoS) by providing a specially crafted PDF file.
Recommendations Update podofo to a version newer than 0.10.5.

Exploit

Fix

DoS

Use After Free

Weakness Enumeration

Related Identifiers

CVE-2025-46205

Affected Products

Debian
Podofo