CVE-2018-5309: Integer Overflow
Published Jan 9, 2018
·Updated
In PoDoFo 0.9.5, there is an integer overflow in the PdfObjectStreamParserObject::ReadObjectsFromStream function (base/PdfObjectStreamParserObject.cpp). Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted pdf file.
Affected Software
1 affected component
Podofo Project Podofo=0.9.5
Event History
Jan 9, 2018
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Data Sourced
via NVD·05:29 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-5309?
CVE-2018-5309 has a high severity rating due to its potential to cause denial-of-service conditions.
2
How do I fix CVE-2018-5309?
To fix CVE-2018-5309, it is recommended to upgrade PoDoFo to the latest patched version.
3
What is the vulnerability CVE-2018-5309 about?
CVE-2018-5309 describes an integer overflow vulnerability in the PdfObjectStreamParserObject::ReadObjectsFromStream function.
4
Can CVE-2018-5309 be exploited remotely?
Yes, CVE-2018-5309 can be exploited remotely through crafted PDF files.
5
Which version of PoDoFo is affected by CVE-2018-5309?
PoDoFo version 0.9.5 is affected by CVE-2018-5309.