First published: Sat Jan 27 2018(Updated: )
In PoDoFo 0.9.5, there is an Excessive Iteration in the PdfParser::ReadObjectsInternal function of base/PdfParser.cpp. Remote attackers could leverage this vulnerability to cause a denial of service through a crafted pdf file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PoDoFo | =0.9.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-6352 is classified as a denial of service vulnerability that can significantly impact the availability of the affected system.
To mitigate CVE-2018-6352, upgrade PoDoFo to version 0.9.6 or later where this issue is addressed.
CVE-2018-6352 specifically affects PoDoFo version 0.9.5, allowing crafted PDF files to cause excessive iterations.
Yes, CVE-2018-6352 can be exploited remotely when a user opens a crafted PDF file.
The impact of CVE-2018-6352 can lead to a denial of service, rendering the affected application unresponsive.