First published: Thu Mar 16 2017(Updated: )
Heap-based buffer overflow in the PdfParser::ReadXRefSubsection function in base/PdfParser.cpp in PoDoFo allows attackers to have unspecified impact via vectors related to m_offsets.size.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PoDoFo |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8981 has a medium severity rating due to the potential for attackers to exploit a heap-based buffer overflow.
To fix CVE-2015-8981, update to the latest version of the PoDoFo library, which addresses the vulnerability.
Exploitation of CVE-2015-8981 can lead to application crashes or arbitrary code execution.
CVE-2015-8981 affects the PoDoFo library prior to the fixed version available in the latest updates.
While CVE-2015-8981 was disclosed in 2015, there have been no widely reported incidents of active exploitation.