mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-13 05:54:46 +02:00
893 B
893 B
CVE-2018-5308
Description
PoDoFo 0.9.5 does not properly validate memcpy arguments in the PdfMemoryOutputStream::Write function (base/PdfOutputStream.cpp). Remote attackers could leverage this vulnerability to cause a denial-of-service or possibly unspecified other impact via a crafted pdf file.
POC
Reference
- https://bugzilla.redhat.com/show_bug.cgi?id=1532390
- https://bugzilla.redhat.com/show_bug.cgi?id=1532390