First published: Fri Mar 09 2018(Updated: )
In PoDoFo 0.9.5, there exists a heap-based buffer over-read vulnerability in UnescapeName() in PdfName.cpp. Remote attackers could leverage this vulnerability to cause a denial-of-service or possibly unspecified other impact via a crafted pdf file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
PoDoFo | =0.9.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-8001 is considered a medium severity vulnerability due to its potential for denial-of-service attacks.
To mitigate CVE-2018-8001, upgrade to a version of PoDoFo later than 0.9.5 where the vulnerability has been addressed.
CVE-2018-8001 is a heap-based buffer over-read vulnerability.
Users of PoDoFo version 0.9.5 are affected by CVE-2018-8001.
Yes, remote attackers could leverage CVE-2018-8001 to perform denial-of-service attacks through crafted PDF files.