A NULL pointer dereference vulnerability exists in the function PdfTranslator::setTarget() in pdftranslator.cpp of PoDoFo 0.9.6, while creating the PdfXObject, as demonstrated by podofoimpose. It allows an attacker to cause Denial of Service.
References
Link | Resource |
---|---|
https://sourceforge.net/p/podofo/tickets/32/ | Exploit Third Party Advisory |
https://research.loginsoft.com/bugs/null-pointer-dereference-vulnerability-in-pdftranslatorsettarget-podofo-0-9-6/ | Exploit Patch Third Party Advisory |
Configurations
Information
Published : 2018-11-25 18:29
Updated : 2018-12-19 06:54
NVD link : CVE-2018-19532
Mitre link : CVE-2018-19532
JSON object : View
CWE
CWE-476
NULL Pointer Dereference
Products Affected
podofo_project
- podofo