REDHAT-BUG-1947458: Buffer Overflow
A flaw was found in PoDoFo. A stack-based buffer overflow in PdfEncryptMD5Base::ComputeOwnerKey function in PdfEncrypt.cpp is possible because of a improper check of the keyLength value.
Reference: https://sourceforge.net/p/podofo/tickets/132/
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1947458?
The severity of REDHAT-BUG-1947458 is classified as critical due to the stack-based buffer overflow vulnerability.
How do I fix REDHAT-BUG-1947458?
To fix REDHAT-BUG-1947458, update the PoDoFo library to the latest version that has patched the vulnerability.
What software is affected by REDHAT-BUG-1947458?
REDHAT-BUG-1947458 affects the PoDoFo library.
What causes the vulnerability in REDHAT-BUG-1947458?
The vulnerability in REDHAT-BUG-1947458 is caused by an improper check of the keyLength value in the PdfEncryptMD5Base::ComputeOwnerKey function.
Can REDHAT-BUG-1947458 lead to remote code execution?
Yes, if exploited, REDHAT-BUG-1947458 can potentially allow remote code execution due to the nature of the buffer overflow.