CVE-2018-19532: Null Pointer Dereference
Published Nov 26, 2018
·Updated
A NULL pointer dereference vulnerability exists in the function PdfTranslator::setTarget() in pdftranslator.cpp of PoDoFo 0.9.6, while creating the PdfXObject, as demonstrated by podofoimpose. It allows an attacker to cause Denial of Service.
Affected Software
1 affected component
Podofo Project Podofo=0.9.6
Remediation
Event History
Nov 26, 2018
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Frequently Asked Questions
1
What is CVE-2018-19532?
CVE-2018-19532 is a NULL pointer dereference vulnerability in the function PdfTranslator::setTarget() in pdftranslator.cpp of PoDoFo 0.9.6.
2
How severe is CVE-2018-19532?
CVE-2018-19532 has a severity value of 8.8, categorized as high.
3
What software versions are affected by CVE-2018-19532?
PoDoFo 0.9.6 is affected by CVE-2018-19532.
4
What is the impact of CVE-2018-19532?
CVE-2018-19532 allows an attacker to cause Denial of Service.
5
Is there a fix available for CVE-2018-19532?
It is recommended to update to a patched version of PoDoFo to mitigate CVE-2018-19532 vulnerability.