CVE-2018-5296

NameCVE-2018-5296
DescriptionIn PoDoFo 0.9.5, there is an uncontrolled memory allocation in the PdfParser::ReadXRefSubsection function (base/PdfParser.cpp). Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted pdf file.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libpodofo (PTS)wheezy0.9.0-1.1vulnerable
wheezy (security)0.9.0-1.1+deb7u2vulnerable
jessie0.9.0-1.2vulnerable
stretch0.9.4-6vulnerable
buster, sid0.9.5-8vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libpodofosource(unstable)(unfixed)

Notes

check, possibly not reported upstream only in Red Hat Bugzilla

Search for package or bug name: Reporting problems