CVE-2018-20797: Buffer Overflow
Published Feb 27, 2019
·Updated
An issue was discovered in PoDoFo 0.9.6. There is an attempted excessive memory allocation in PoDoFo::podofocalloc in base/PdfMemoryManagement.cpp when called from PoDoFo::PdfPredictorDecoder::PdfPredictorDecoder in base/PdfFiltersPrivate.cpp.
Affected Software
2 affected components
debian/libpodofo<=0.9.7+dfsg-2, <=0.9.8+dfsg-3, <=0.9.8+dfsg-3.2
Podofo Project Podofo=0.9.6
Event History
Feb 27, 2019
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Jan 20, 2025
Data Sourced
via Launchpad·05:23 AM
Description
Jan 24, 2025
Data Sourced
via Ubuntu·05:23 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-20797?
CVE-2018-20797 is classified as a high severity vulnerability due to the potential for excessive memory allocation.
2
How do I fix CVE-2018-20797?
To remediate CVE-2018-20797, upgrade to a version of PoDoFo that is newer than 0.9.8.
3
What software is affected by CVE-2018-20797?
CVE-2018-20797 affects PoDoFo version 0.9.6 and certain versions of the libpodofo package.
4
What is the potential impact of CVE-2018-20797?
The potential impact of CVE-2018-20797 includes denial of service due to excessive memory allocation.
5
When was CVE-2018-20797 last updated?
CVE-2018-20797 was last updated on January 20, 2025.