CVE-2018-5308 - log back

CVE-2018-5308 edited at 10 Jan 2021 10:42:13
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Local
Type
- Unknown
+ Arbitrary code execution
Description
+ PoDoFo 0.9.5 does not properly validate memcpy arguments in the PdfMemoryOutputStream::Write function (base/PdfOutputStream.cpp). Remote attackers could leverage this vulnerability to cause a denial-of-service or possibly unspecified other impact via a crafted pdf file.
References
+ https://bugzilla.redhat.com/show_bug.cgi?id=1532390
+ https://bugzilla.redhat.com/attachment.cgi?id=1378732
+ https://sourceforge.net/p/podofo/code/1876/
CVE-2018-5308 created at 10 Jan 2021 10:40:34
Severity
+ Unknown
Remote
+ Unknown
Type
+ Unknown
Description
References
Notes