Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-8001

Опубликовано: 09 мар. 2018
Источник: debian

Описание

In PoDoFo 0.9.5, there exists a heap-based buffer over-read vulnerability in UnescapeName() in PdfName.cpp. Remote attackers could leverage this vulnerability to cause a denial-of-service or possibly unspecified other impact via a crafted pdf file.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libpodofofixed0.9.6+dfsg-3package
libpodofono-dsastretchpackage
libpodofono-dsajessiepackage
libpodofono-dsawheezypackage

Примечания

  • PoC https://bugzilla.redhat.com/show_bug.cgi?id=1549469

  • Upstream bug: https://sourceforge.net/p/podofo/tickets/14/

  • Upstream commit: http://sourceforge.net/p/podofo/code/1909

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 7 лет назад

In PoDoFo 0.9.5, there exists a heap-based buffer over-read vulnerability in UnescapeName() in PdfName.cpp. Remote attackers could leverage this vulnerability to cause a denial-of-service or possibly unspecified other impact via a crafted pdf file.

CVSS3: 7.8
nvd
больше 7 лет назад

In PoDoFo 0.9.5, there exists a heap-based buffer over-read vulnerability in UnescapeName() in PdfName.cpp. Remote attackers could leverage this vulnerability to cause a denial-of-service or possibly unspecified other impact via a crafted pdf file.

CVSS3: 7.8
github
больше 3 лет назад

In PoDoFo 0.9.5, there exists a heap-based buffer over-read vulnerability in UnescapeName() in PdfName.cpp. Remote attackers could leverage this vulnerability to cause a denial-of-service or possibly unspecified other impact via a crafted pdf file.

suse-cvrf
около 1 года назад

Security update for podofo

suse-cvrf
около 7 лет назад

Security update for podofo