CVE-2023-31567: Buffer Overflow
Published May 10, 2023
·Updated
Podofo v0.10.0 was discovered to contain a heap buffer overflow via the component PoDoFo::PdfEncryptAESV3::PdfEncryptAESV3.
Affected Software
1 affected component
Podofo Project Podofo=0.10.0
Remediation
Patch Available
Event History
May 10, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-31567?
CVE-2023-31567 has been classified with a high severity rating due to the potential exploitation of a heap buffer overflow.
2
How do I fix CVE-2023-31567?
To fix CVE-2023-31567, it is recommended to upgrade to a patched version of PoDoFo that addresses the heap buffer overflow vulnerability.
3
What component is affected by CVE-2023-31567?
CVE-2023-31567 affects the PoDoFo::PdfEncryptAESV3::PdfEncryptAESV3 component within PoDoFo v0.10.0.
4
Can CVE-2023-31567 be exploited remotely?
Yes, CVE-2023-31567 can potentially be exploited remotely if an attacker can send specially crafted files to vulnerable applications.
5
Is CVE-2023-31567 present in versions other than 0.10.0?
CVE-2023-31567 is specifically identified in PoDoFo version 0.10.0, and other versions may not be directly affected.