First published: Fri Jun 29 2018(Updated: )
A stack-based buffer over-read in the PdfEncryptMD5Base::ComputeEncryptionKey() function in PdfEncrypt.cpp in PoDoFo 0.9.6-rc1 could be leveraged by remote attackers to cause a denial-of-service via a crafted pdf file.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/libpodofo | <=0.9.7+dfsg-2 | 0.9.8+dfsg-3 0.9.8+dfsg-3.2 |
PoDoFo project PoDoFo | =0.9.6-rc1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.