CVE-2021-30470: Medium severity podofo vulnerability
A flaw was found in PoDoFo 0.9.7. An uncontrolled recursive call among PdfTokenizer::ReadArray(), PdfTokenizer::GetNextVariant() and PdfTokenizer::ReadDataType() functions can lead to a stack overflow.
Other sources
A flaw was found in PoDoFo. An uncontrolled recursive call among PdfTokenizer::ReadArray(), PdfTokenizer::GetNextVariant() and PdfTokenizer::ReadDataType() functions can lead to a stack overflow.
Reference: https://sourceforge.net/p/podofo/tickets/130/
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-30470?
CVE-2021-30470 has a medium severity rating due to the potential for a stack overflow vulnerability.
What software is affected by CVE-2021-30470?
CVE-2021-30470 affects versions of PoDoFo up to 0.9.7 and versions of libpodofo in Debian, as well as specific versions on Red Hat Enterprise Linux and Fedora.
How do I fix CVE-2021-30470?
To fix CVE-2021-30470, you should upgrade to the latest version of PoDoFo and ensure that your package manager has the updated libpodofo.
What is the risk associated with CVE-2021-30470?
The risk associated with CVE-2021-30470 is that an attacker could exploit the stack overflow to execute arbitrary code or crash the application.
Can CVE-2021-30470 be exploited remotely?
Yes, CVE-2021-30470 can potentially be exploited remotely if a malicious PDF is processed by vulnerable versions of the affected software.