PoDoFo::Impose::PdfTranslator::setSource() in pdftranslator.cpp in PoDoFo 0.9.6 has a NULL pointer dereference that can (for example) be triggered by sending a crafted PDF file to the podofoimpose binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.
References
Link | Resource |
---|---|
https://sourceforge.net/p/podofo/tickets/40/ | Exploit Third Party Advisory |
https://research.loginsoft.com/bugs/null-pointer-dereference-vulnerability-in-setsource-podofo-0-9-6-trunk-r1967/ | Exploit Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NTJ5AAM6Y4NMSELEH7N5ZG4DNO56BCYF/ | Mailing List Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CIC2EXSSMBT3MY2HY42IIY4BUQS2SVYB/ | Mailing List Third Party Advisory |
Information
Published : 2019-02-26 15:29
Updated : 2019-04-03 06:42
NVD link : CVE-2019-9199
Mitre link : CVE-2019-9199
JSON object : View
CWE
CWE-476
NULL Pointer Dereference
Products Affected
podofo_project
- podofo
fedoraproject
- fedora