First published: Thu Apr 08 2021(Updated: )
A flaw was found in PoDoFo 0.9.7. An use-after-free in PoDoFo::PdfVecObjects::Clear() function can cause a denial of service via a crafted PDF file.
Credit: patrick@puiterwijk.org
Affected Software | Affected Version | How to fix |
---|---|---|
PoDoFo | =0.9.7 | |
Fedora | =33 | |
Red Hat Enterprise Linux | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-30469 has a severity rating that may lead to denial of service due to the exploitability of a use-after-free vulnerability.
To fix CVE-2021-30469, make sure to update PoDoFo to version 0.9.8 or later, which contains the patch for this vulnerability.
CVE-2021-30469 affects PoDoFo version 0.9.7, as well as certain Fedora and Red Hat Enterprise Linux distributions.
CVE-2021-30469 is classified as a use-after-free vulnerability leading to potential denial of service.
Yes, CVE-2021-30469 can potentially be exploited remotely through the processing of a crafted PDF file.