First published: Fri May 18 2018(Updated: )
An issue was discovered in PoDoFo 0.9.5. The function PdfDocument::Append() in PdfDocument.cpp in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PDF document.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PoDoFo | =0.9.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-11256 is classified as a denial of service vulnerability.
To fix CVE-2018-11256, you should update PoDoFo to a version later than 0.9.5 that addresses this vulnerability.
CVE-2018-11256 is caused by a NULL pointer dereference in the PdfDocument::Append() function of PoDoFo 0.9.5.
CVE-2018-11256 affects users of PoDoFo version 0.9.5.
The impact of CVE-2018-11256 is that remote attackers can crash the application by sending a crafted PDF document.