First published: Fri May 18 2018(Updated: )
An issue was discovered in PoDoFo 0.9.5. There is an Excessive Recursion in the PdfPagesTree::GetPageNode() function of PdfPagesTree.cpp. Remote attackers could leverage this vulnerability to cause a denial of service through a crafted pdf file, a related issue to CVE-2017-8054.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PoDoFo | =0.9.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-11254 has been classified as a high severity vulnerability due to its potential to cause denial of service.
The best way to fix CVE-2018-11254 is to update PoDoFo to the latest version, ideally beyond 0.9.5.
CVE-2018-11254 facilitates denial of service attacks via excessive recursion in the PdfPagesTree::GetPageNode() function.
Individuals and organizations using PoDoFo version 0.9.5 are at risk of being affected by CVE-2018-11254.
Yes, CVE-2018-11254 can be exploited remotely by attackers using a crafted PDF file.