CVE-2019-20093: Null Pointer Dereference
Published Dec 30, 2019
·Updated
The PoDoFo::PdfVariant::DelayedLoad function in PdfVariant.h in PoDoFo 0.9.6 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file, because of ImageExtractor.cpp.
Affected Software
3 affected components
Podofo Project Podofo=0.9.6
fedoraproject fedora=30
fedoraproject fedora=31
Event History
Dec 30, 2019
CVE Published
via MITRE·03:47 AM
Data Sourced
via MITRE·03:47 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-20093?
CVE-2019-20093 has a severity rating that indicates it can lead to a denial of service due to a NULL pointer dereference.
2
How do I fix CVE-2019-20093?
To fix CVE-2019-20093, update to the latest version of PoDoFo or apply the specific patches provided by the software maintainers.
3
What software is affected by CVE-2019-20093?
CVE-2019-20093 affects PoDoFo version 0.9.6 and Fedora versions 30 and 31.
4
What type of attack does CVE-2019-20093 enable?
CVE-2019-20093 enables remote attackers to cause a denial of service condition.
5
What component is involved in CVE-2019-20093 vulnerability?
The vulnerability in CVE-2019-20093 is located in the PoDoFo::PdfVariant::DelayedLoad function within the PdfVariant.h file.