CVE-2018-19532 — NULL Pointer Dereference in Project Podofo
Severity
8.8HIGHNVD
EPSS
0.3%
top 43.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 26
Latest updateMay 14
Description
A NULL pointer dereference vulnerability exists in the function PdfTranslator::setTarget() in pdftranslator.cpp of PoDoFo 0.9.6, while creating the PdfXObject, as demonstrated by podofoimpose. It allows an attacker to cause Denial of Service.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9
Affected Packages2 packages
Patches
🔴Vulnerability Details
2📋Vendor Advisories
1Debian▶
CVE-2018-19532: libpodofo - A NULL pointer dereference vulnerability exists in the function PdfTranslator::s...↗2018
💬Community
3Bugzilla▶
CVE-2018-19532 podofo: NULL pointer dereference in PdfTranslator::setTarget() in pdftranslator.cpp [epel-all]↗2018-12-04
Bugzilla▶
CVE-2018-19532 podofo: NULL pointer dereference in PdfTranslator::setTarget() in pdftranslator.cpp↗2018-12-04
Bugzilla▶
CVE-2018-19532 podofo: NULL pointer dereference in PdfTranslator::setTarget() in pdftranslator.cpp [fedora-all]↗2018-12-04