CVE-2018-11254: Medium severity podofo vulnerability
An issue was discovered in PoDoFo 0.9.5. There is an Excessive Recursion in the PdfPagesTree::GetPageNode() function of PdfPagesTree.cpp. Remote attackers could leverage this vulnerability to cause a denial of service through a crafted pdf file, a related issue to CVE-2017-8054.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-11254?
CVE-2018-11254 has been classified as a high severity vulnerability due to its potential to cause denial of service.
How do I fix CVE-2018-11254?
The best way to fix CVE-2018-11254 is to update PoDoFo to the latest version, ideally beyond 0.9.5.
What type of attack does CVE-2018-11254 facilitate?
CVE-2018-11254 facilitates denial of service attacks via excessive recursion in the PdfPagesTree::GetPageNode() function.
Who is affected by CVE-2018-11254?
Individuals and organizations using PoDoFo version 0.9.5 are at risk of being affected by CVE-2018-11254.
Can CVE-2018-11254 be exploited remotely?
Yes, CVE-2018-11254 can be exploited remotely by attackers using a crafted PDF file.