CVE-2018-8001: High severity Podofo Project Podofo vulnerability
Published Mar 9, 2018
·Updated
In PoDoFo 0.9.5, there exists a heap-based buffer over-read vulnerability in UnescapeName() in PdfName.cpp. Remote attackers could leverage this vulnerability to cause a denial-of-service or possibly unspecified other impact via a crafted pdf file.
Affected Software
1 affected component
Podofo Project Podofo=0.9.5
Event History
Mar 9, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
via NVD·07:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-8001?
CVE-2018-8001 is considered a medium severity vulnerability due to its potential for denial-of-service attacks.
2
How do I fix CVE-2018-8001?
To mitigate CVE-2018-8001, upgrade to a version of PoDoFo later than 0.9.5 where the vulnerability has been addressed.
3
What type of vulnerability is CVE-2018-8001?
CVE-2018-8001 is a heap-based buffer over-read vulnerability.
4
Who is affected by CVE-2018-8001?
Users of PoDoFo version 0.9.5 are affected by CVE-2018-8001.
5
Can CVE-2018-8001 lead to exploits?
Yes, remote attackers could leverage CVE-2018-8001 to perform denial-of-service attacks through crafted PDF files.