First published: Tue Jan 09 2018(Updated: )
In PoDoFo 0.9.5, there is an integer overflow in the PdfObjectStreamParserObject::ReadObjectsFromStream function (base/PdfObjectStreamParserObject.cpp). Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted pdf file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PoDoFo | =0.9.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-5309 has a high severity rating due to its potential to cause denial-of-service conditions.
To fix CVE-2018-5309, it is recommended to upgrade PoDoFo to the latest patched version.
CVE-2018-5309 describes an integer overflow vulnerability in the PdfObjectStreamParserObject::ReadObjectsFromStream function.
Yes, CVE-2018-5309 can be exploited remotely through crafted PDF files.
PoDoFo version 0.9.5 is affected by CVE-2018-5309.