PoDoFo 0.9.6 has a heap-based buffer overflow in PdfString::ConvertUTF16toUTF8 in base/PdfString.cpp.
References
Link | Resource |
---|---|
https://sourceforge.net/p/podofo/code/1969 | Patch Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NTJ5AAM6Y4NMSELEH7N5ZG4DNO56BCYF/ | Mailing List Release Notes Third Party Advisory |
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CIC2EXSSMBT3MY2HY42IIY4BUQS2SVYB/ |
Information
Published : 2019-03-11 09:29
Updated : 2020-08-24 10:37
NVD link : CVE-2019-9687
Mitre link : CVE-2019-9687
JSON object : View
CWE
CWE-787
Out-of-bounds Write
Products Affected
podofo_project
- podofo
fedoraproject
- fedora