CVE-2021-30472: Buffer Overflow
A flaw was found in PoDoFo 0.9.7. A stack-based buffer overflow in PdfEncryptMD5Base::ComputeOwnerKey function in PdfEncrypt.cpp is possible because of a improper check of the keyLength value.
Other sources
A flaw was found in PoDoFo. A stack-based buffer overflow in PdfEncryptMD5Base::ComputeOwnerKey function in PdfEncrypt.cpp is possible because of a improper check of the keyLength value.
Reference: https://sourceforge.net/p/podofo/tickets/132/
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-30472?
CVE-2021-30472 is classified as a high severity vulnerability due to the potential for stack-based buffer overflow.
How do I fix CVE-2021-30472?
To mitigate CVE-2021-30472, upgrade PoDoFo to the latest version that addresses this buffer overflow issue.
What software is affected by CVE-2021-30472?
CVE-2021-30472 affects PoDoFo version 0.9.7.
What type of vulnerability is CVE-2021-30472?
CVE-2021-30472 is a stack-based buffer overflow vulnerability.
When was CVE-2021-30472 published?
CVE-2021-30472 was published in 2021.