CVE-2017-8054 log
| Source |
|
| Severity | Low |
| Remote | No |
| Type | Denial of service |
| Description | The function PdfPagesTree::GetPageNodeFromArray in PdfPageTree.cpp:464 in PoDoFo 0.9.6 allows remote attackers to cause a denial of service (infinite recursion and application crash) via a crafted PDF document. The issue is fixed in PoDoFo version 0.9.7. |
| Group | Package | Affected | Fixed | Severity | Status | Ticket |
|---|---|---|---|---|---|---|
| AVG-867 | podofo | 0.9.6-3 | 0.9.7-1 | Medium | Fixed | FS#61651 |
| Date | Advisory | Group | Package | Severity | Type |
|---|---|---|---|---|---|
| 20 Jan 2021 | ASA-202101-36 | AVG-867 | podofo | Medium | multiple issues |
| References |
|---|
https://qwertwwwe.github.io/2017/04/22/PoDoFo-0-9-5-allows-remote-attackers-to-cause-a-denial-of-service-infinit-loop/ https://sourceforge.net/p/podofo/code/1941/ |