CVE-2019-10723: Medium severity podofo vulnerability
Published Apr 3, 2019
·Updated
An issue was discovered in PoDoFo 0.9.6. The PdfPagesTreeCache class in doc/PdfPagesTreeCache.cpp has an attempted excessive memory allocation because nInitialSize is not validated.
Affected Software
2 affected componentsFixes available
debian/libpodofo<=0.9.7+dfsg-2
0.9.8+dfsg-30.9.8+dfsg-3.2
Podofo Project Podofo=0.9.6
Event History
Apr 3, 2019
CVE Published
via MITRE·05:01 PM
Data Sourced
via MITRE·05:01 PM
Description
Data Sourced
via NVD·06:29 PM
DescriptionSeverityWeaknessAffected Software
Jan 24, 2025
Data Sourced
via Ubuntu·05:23 AM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·05:23 AM
Description
Data Sourced
via Debian·05:24 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-10723?
CVE-2019-10723 has a moderate severity rating due to its potential for excessive memory allocation.
2
How do I fix CVE-2019-10723?
To fix CVE-2019-10723, upgrade to PoDoFo version 0.9.8 or later.
3
What causes the CVE-2019-10723 vulnerability?
The vulnerability in CVE-2019-10723 is caused by insufficient validation of the initial size parameter in memory allocation.
4
Which versions of PoDoFo are affected by CVE-2019-10723?
CVE-2019-10723 affects PoDoFo versions up to and including 0.9.6.
5
Is CVE-2019-10723 present in Debian packages?
Yes, CVE-2019-10723 is present in Debian packages of libpodofo before version 0.9.8+dfsg-3.