CVE-2017-5855: Null Pointer Dereference
Published Mar 1, 2017
·Updated
The PoDoFo::PdfParser::ReadXRefSubsection function in PdfParser.cpp in PoDoFo 0.9.4 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.
Affected Software
1 affected component
Podofo Project Podofo=0.9.4
Event History
Mar 1, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-5855?
CVE-2017-5855 has a severity rating of medium due to its potential for denial of service.
2
How do I fix CVE-2017-5855?
To fix CVE-2017-5855, upgrade to a version of PoDoFo later than 0.9.4 that addresses this vulnerability.
3
What types of attacks are possible with CVE-2017-5855?
CVE-2017-5855 allows remote attackers to cause a denial of service through a crafted PDF file.
4
In which version of PoDoFo does CVE-2017-5855 occur?
CVE-2017-5855 affects PoDoFo version 0.9.4.
5
What component of PoDoFo is affected by CVE-2017-5855?
CVE-2017-5855 affects the PdfParser.cpp component in the PoDoFo library.