First published: Mon Jan 08 2018(Updated: )
In PoDoFo 0.9.5, there is an integer overflow in the PdfXRefStreamParserObject::ParseStream function (base/PdfXRefStreamParserObject.cpp). Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted pdf file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PoDoFo | =0.9.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-5295 is rated as a moderate severity vulnerability.
To fix CVE-2018-5295, upgrade PoDoFo to a version higher than 0.9.5.
CVE-2018-5295 can be exploited by remote attackers to perform denial-of-service attacks.
CVE-2018-5295 specifically affects PoDoFo version 0.9.5.
The vulnerability in CVE-2018-5295 is caused by an integer overflow in the PdfXRefStreamParserObject::ParseStream function.