First published: Fri Jun 29 2018(Updated: )
Invalid memory read in the PoDoFo::PdfVariant::DelayedLoad() function in PdfVariant.h in PoDoFo 0.9.6-rc1 allows remote attackers to have denial-of-service impact via a crafted file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PoDoFo | =0.9.6-rc1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-12982 is rated as a medium severity vulnerability due to its potential to cause denial-of-service attacks.
To fix CVE-2018-12982, you should upgrade to a version of PoDoFo greater than 0.9.6-rc1.
CVE-2018-12982 is caused by an invalid memory read in the DelayedLoad() function in PdfVariant.h.
Yes, CVE-2018-12982 can be exploited remotely via crafted files.
CVE-2018-12982 specifically affects PoDoFo version 0.9.6-rc1.