Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:2309-1

Опубликовано: 09 июн. 2026
Источник: suse-cvrf

Описание

Security update for podofo

This update for podofo fixes the following issue:

  • CVE-2026-44348: double-free in compute_hash_to_sign() in src/podofo/private/OpenSSLInternal_Ripped.cpp (bsc#1265320).

Список пакетов

SUSE Linux Enterprise Module for Package Hub 15 SP7
libpodofo-devel-1.0.2-150700.3.6.1

Описание

PoDoFo is a C++17 PDF manipulation library. From 1.0.0 to before 1.0.4, a double-free vulnerability exists in compute_hash_to_sign() in src/podofo/private/OpenSSLInternal_Ripped.cpp. If EVP_DigestFinal fails after buf has already been freed, the Error label frees buf a second time, causing heap corruption. This vulnerability is fixed in 1.0.4.


Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP7:libpodofo-devel-1.0.2-150700.3.6.1

Ссылки