First published: Wed Feb 27 2019(Updated: )
An issue was discovered in PoDoFo 0.9.6. There is an attempted excessive memory allocation in PoDoFo::podofo_calloc in base/PdfMemoryManagement.cpp when called from PoDoFo::PdfPredictorDecoder::PdfPredictorDecoder in base/PdfFiltersPrivate.cpp.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/libpodofo | <=0.9.7+dfsg-2<=0.9.8+dfsg-3<=0.9.8+dfsg-3.2 | |
PoDoFo | =0.9.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-20797 is classified as a high severity vulnerability due to the potential for excessive memory allocation.
To remediate CVE-2018-20797, upgrade to a version of PoDoFo that is newer than 0.9.8.
CVE-2018-20797 affects PoDoFo version 0.9.6 and certain versions of the libpodofo package.
The potential impact of CVE-2018-20797 includes denial of service due to excessive memory allocation.
CVE-2018-20797 was last updated on January 20, 2025.