First published: Sat Apr 22 2017(Updated: )
PoDoFo 0.9.5 allows denial of service (infinite recursion and stack consumption) via a crafted PDF file in PoDoFo::PdfParser::ReadDocumentStructure (PdfParser.cpp).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PoDoFo | =0.9.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8053 has been assigned a medium severity rating due to its potential for causing denial of service.
To fix CVE-2017-8053, update to a version of PoDoFo that addresses this vulnerability.
CVE-2017-8053 is classified as a denial of service vulnerability.
CVE-2017-8053 causes infinite recursion and stack consumption, leading to a denial of service.
Yes, CVE-2017-8053 is triggered by a crafted PDF file processed by PoDoFo.