CVE-2018-8002
PoDoFo 0.9.5 - Buffer Overflow (PoC)
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
In PoDoFo 0.9.5, there exists an infinite loop vulnerability in PdfParserObject::ParseFileComplete() in PdfParserObject.cpp which may result in stack overflow. Remote attackers could leverage this vulnerability to cause a denial-of-service or possibly unspecified other impact via a crafted pdf file.
En PoDoFo 0.9.5, existe una vulnerabilidad de bucle infinito en PdfParserObject::ParseFileComplete() en PdfParserObject.cpp, lo que podrÃa resultar en un desbordamiento de pila. Los atacantes remotos pueden aprovechar esta vulnerabilidad para provocar una denegación de servicio (DoS) o, posiblemente, otro tipo de impacto sin especificar mediante un archivo pdf manipulado.
PoDoFo version 0.9.5 suffers from a buffer overflow vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-03-09 CVE Reserved
- 2018-03-09 CVE Published
- 2024-02-17 EPSS Updated
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop')
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=1548930 | Issue Tracking |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/44946 | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Podofo Project Search vendor "Podofo Project" | Podofo Search vendor "Podofo Project" for product "Podofo" | 0.9.5 Search vendor "Podofo Project" for product "Podofo" and version "0.9.5" | - |
Affected
|