First published: Fri Jun 29 2018(Updated: )
A stack-based buffer over-read in the PdfEncryptMD5Base::ComputeEncryptionKey() function in PdfEncrypt.cpp in PoDoFo 0.9.6-rc1 could be leveraged by remote attackers to cause a denial-of-service via a crafted pdf file.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/libpodofo | <=0.9.7+dfsg-2 | 0.9.8+dfsg-3 0.9.8+dfsg-3.2 |
PoDoFo | =0.9.6-rc1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-12983 has a medium severity rating due to its potential for denial-of-service attacks.
To fix CVE-2018-12983, update to the latest version of PoDoFo, specifically versions later than 0.9.7+dfsg-2.
CVE-2018-12983 affects PoDoFo version 0.9.6-rc1 and the libpodofo package in Debian versions up to 0.9.7+dfsg-2.
Yes, CVE-2018-12983 can be exploited remotely through the use of a crafted PDF file.
Yes, CVE-2018-12983 is a known vulnerability that has been publicly reported and documented.