Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-7994

Опубликовано: 21 апр. 2017
Источник: debian

Описание

The function TextExtractor::ExtractText in TextExtractor.cpp:77 in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PDF document.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libpodofofixed0.9.5-7package
libpodofono-dsastretchpackage
libpodofono-dsajessiepackage
libpodofono-dsawheezypackage

Примечания

  • https://github.com/icepng/PoC/tree/master/PoC1

  • https://icepng.github.io/2017/04/21/PoDoFo-1/

  • upstream commit: https://sourceforge.net/p/podofo/code/1849

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 9 лет назад

The function TextExtractor::ExtractText in TextExtractor.cpp:77 in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PDF document.

CVSS3: 6.5
nvd
почти 9 лет назад

The function TextExtractor::ExtractText in TextExtractor.cpp:77 in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PDF document.

CVSS3: 6.5
github
больше 3 лет назад

The function TextExtractor::ExtractText in TextExtractor.cpp:77 in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PDF document.

suse-cvrf
больше 7 лет назад

Security update for podofo

suse-cvrf
около 7 лет назад

Security update for podofo