CVE-2018-12983: High severity podofo vulnerability
Published Jun 29, 2018
·Updated
A stack-based buffer over-read in the PdfEncryptMD5Base::ComputeEncryptionKey() function in PdfEncrypt.cpp in PoDoFo 0.9.6-rc1 could be leveraged by remote attackers to cause a denial-of-service via a crafted pdf file.
Affected Software
2 affected componentsFixes available
debian/libpodofo<=0.9.7+dfsg-2
0.9.8+dfsg-30.9.8+dfsg-3.2
Podofo Project Podofo=0.9.6-rc1
Event History
Jun 29, 2018
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Jan 20, 2025
Data Sourced
via Launchpad·05:23 AM
Description
Jan 24, 2025
Data Sourced
via Ubuntu·05:23 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-12983?
CVE-2018-12983 has a medium severity rating due to its potential for denial-of-service attacks.
2
How do I fix CVE-2018-12983?
To fix CVE-2018-12983, update to the latest version of PoDoFo, specifically versions later than 0.9.7+dfsg-2.
3
What software is affected by CVE-2018-12983?
CVE-2018-12983 affects PoDoFo version 0.9.6-rc1 and the libpodofo package in Debian versions up to 0.9.7+dfsg-2.
4
Can CVE-2018-12983 be exploited remotely?
Yes, CVE-2018-12983 can be exploited remotely through the use of a crafted PDF file.
5
Is CVE-2018-12983 a known vulnerability?
Yes, CVE-2018-12983 is a known vulnerability that has been publicly reported and documented.