First published: Fri Mar 09 2018(Updated: )
In PoDoFo 0.9.5, there exists an infinite loop vulnerability in PdfParserObject::ParseFileComplete() in PdfParserObject.cpp which may result in stack overflow. Remote attackers could leverage this vulnerability to cause a denial-of-service or possibly unspecified other impact via a crafted pdf file.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/libpodofo | <=0.9.7+dfsg-2<=0.9.8+dfsg-3<=0.9.8+dfsg-3.2 | |
PoDoFo | =0.9.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-8002 is classified as a denial-of-service vulnerability that leads to an infinite loop and potential stack overflow.
The recommended fix for CVE-2018-8002 is to update to a version of PoDoFo that is newer than 0.9.7.
CVE-2018-8002 affects PoDoFo version 0.9.5, as well as specific versions of the libpodofo package included in Debian.
Yes, remote attackers can exploit CVE-2018-8002 by providing a crafted PDF file to trigger the infinite loop.
The potential impacts of CVE-2018-8002 include denial-of-service attacks and possible unspecified other effects.