CVE-2017-5854: Null Pointer Dereference
Published Mar 1, 2017
·Updated
base/PdfOutputStream.cpp in PoDoFo 0.9.4 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted file.
Affected Software
1 affected component
Podofo Project Podofo=0.9.4
Event History
Mar 1, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-5854?
CVE-2017-5854 is classified as a denial of service vulnerability.
2
How do I fix CVE-2017-5854?
To fix CVE-2017-5854, update PoDoFo to version 0.9.5 or later.
3
What systems are affected by CVE-2017-5854?
CVE-2017-5854 affects PoDoFo version 0.9.4.
4
What type of attack does CVE-2017-5854 facilitate?
CVE-2017-5854 allows remote attackers to execute a denial of service attack through a crafted file.
5
Can CVE-2017-5854 be exploited without user interaction?
Yes, CVE-2017-5854 can be exploited by sending a specially crafted file to the target.