CVE-2018-5296: Medium severity Podofo Project Podofo vulnerability
Published Jan 8, 2018
·Updated
In PoDoFo 0.9.5, there is an uncontrolled memory allocation in the PdfParser::ReadXRefSubsection function (base/PdfParser.cpp). Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted pdf file.
Affected Software
1 affected component
Podofo Project Podofo=0.9.5
Event History
Jan 8, 2018
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Data Sourced
via NVD·07:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-5296?
CVE-2018-5296 is classified as a denial-of-service vulnerability.
2
How do I fix CVE-2018-5296?
To fix CVE-2018-5296, upgrade to a patched version of PoDoFo that addresses the uncontrolled memory allocation issue.
3
What does CVE-2018-5296 affect?
CVE-2018-5296 affects PoDoFo version 0.9.5.
4
Can CVE-2018-5296 be exploited remotely?
Yes, CVE-2018-5296 can be exploited by remote attackers via a specially crafted PDF file.
5
What is the risk associated with CVE-2018-5296?
The risk associated with CVE-2018-5296 is potential denial-of-service, which may disrupt the functionality of affected systems.