CVE-2019-9687: Buffer Overflow
Published Mar 11, 2019
·Updated
PoDoFo 0.9.6 has a heap-based buffer overflow in PdfString::ConvertUTF16toUTF8 in base/PdfString.cpp.
Affected Software
2 affected components
Podofo Project Podofo=0.9.6
fedoraproject fedora=29
Remediation
Patch Available
Event History
Mar 11, 2019
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Data Sourced
via NVD·04:29 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2019-9687?
CVE-2019-9687 is classified as a high severity vulnerability due to its potential to cause a heap-based buffer overflow.
2
How do I fix CVE-2019-9687?
To fix CVE-2019-9687, update to the latest version of PoDoFo or apply any available patches that address this vulnerability.
3
What software is affected by CVE-2019-9687?
CVE-2019-9687 specifically affects PoDoFo version 0.9.6 and Fedora version 29.
4
Is CVE-2019-9687 a remote exploitation vulnerability?
CVE-2019-9687 can be exploited remotely, making it critical to patch affected systems as soon as possible.
5
What protocols are impacted by CVE-2019-9687?
CVE-2019-9687 impacts applications that utilize PoDoFo to handle PDF files, particularly in how they process strings.