CVE-2017-6840: Medium severity Podofo Project Podofo vulnerability
Published Mar 15, 2017
·Updated
The ColorChanger::GetColorFromStack function in colorchanger.cpp in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (invalid read) via a crafted file.
Affected Software
1 affected component
Podofo Project Podofo=0.9.5
Event History
Mar 15, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-6840?
CVE-2017-6840 has been classified as a moderate severity vulnerability.
2
How does CVE-2017-6840 affect PoDoFo 0.9.5?
CVE-2017-6840 allows remote attackers to cause a denial of service through an invalid read in the ColorChanger::GetColorFromStack function.
3
Can CVE-2017-6840 be exploited remotely?
Yes, CVE-2017-6840 can be exploited remotely using a specially crafted file.
4
What is the impact of exploiting CVE-2017-6840?
Exploiting CVE-2017-6840 can lead to a denial of service affecting the availability of the application.
5
How can I mitigate CVE-2017-6840?
To mitigate CVE-2017-6840, it is recommended to upgrade to a version of PoDoFo that is not vulnerable.