Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-20751

Опубликовано: 04 фев. 2019
Источник: debian
EPSS Низкий

Описание

An issue was discovered in crop_page in PoDoFo 0.9.6. For a crafted PDF document, pPage->GetObject()->GetDictionary().AddKey(PdfName("MediaBox"),var) can be problematic due to the function GetObject() being called for the pPage NULL pointer object. The value of pPage at this point is 0x0, which causes a NULL pointer dereference.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libpodofofixed0.9.6+dfsg-4package
libpodofono-dsastretchpackage
libpodofono-dsajessiepackage

Примечания

  • https://sourceforge.net/p/podofo/tickets/33/

  • https://sourceforge.net/p/podofo/code/1954

EPSS

Процентиль: 63%
0.00437
Низкий

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 7 лет назад

An issue was discovered in crop_page in PoDoFo 0.9.6. For a crafted PDF document, pPage->GetObject()->GetDictionary().AddKey(PdfName("MediaBox"),var) can be problematic due to the function GetObject() being called for the pPage NULL pointer object. The value of pPage at this point is 0x0, which causes a NULL pointer dereference.

CVSS3: 8.8
nvd
около 7 лет назад

An issue was discovered in crop_page in PoDoFo 0.9.6. For a crafted PDF document, pPage->GetObject()->GetDictionary().AddKey(PdfName("MediaBox"),var) can be problematic due to the function GetObject() being called for the pPage NULL pointer object. The value of pPage at this point is 0x0, which causes a NULL pointer dereference.

CVSS3: 8.8
github
больше 3 лет назад

An issue was discovered in crop_page in PoDoFo 0.9.6. For a crafted PDF document, pPage->GetObject()->GetDictionary().AddKey(PdfName("MediaBox"),var) can be problematic due to the function GetObject() being called for the pPage NULL pointer object. The value of pPage at this point is 0x0, which causes a NULL pointer dereference.

CVSS3: 8.8
fstec
около 7 лет назад

Уязвимость функции crop_page() программной библиотеки PoDoFo, позволяющая нарушителю вызвать отказ в обслуживании

suse-cvrf
больше 6 лет назад

Security update for podofo

EPSS

Процентиль: 63%
0.00437
Низкий