CVE-2018-11256: Null Pointer Dereference
Published May 18, 2018
·Updated
An issue was discovered in PoDoFo 0.9.5. The function PdfDocument::Append() in PdfDocument.cpp in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PDF document.
Affected Software
1 affected component
Podofo Project Podofo=0.9.5
Event History
May 18, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-11256?
CVE-2018-11256 is classified as a denial of service vulnerability.
2
How do I fix CVE-2018-11256?
To fix CVE-2018-11256, you should update PoDoFo to a version later than 0.9.5 that addresses this vulnerability.
3
What causes the issue in CVE-2018-11256?
CVE-2018-11256 is caused by a NULL pointer dereference in the PdfDocument::Append() function of PoDoFo 0.9.5.
4
Who is affected by CVE-2018-11256?
CVE-2018-11256 affects users of PoDoFo version 0.9.5.
5
What is the impact of CVE-2018-11256?
The impact of CVE-2018-11256 is that remote attackers can crash the application by sending a crafted PDF document.