CVE-2018-19532NULL Pointer Dereference in Project Podofo

Severity
8.8HIGHNVD
EPSS
0.3%
top 43.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 26
Latest updateMay 14

Description

A NULL pointer dereference vulnerability exists in the function PdfTranslator::setTarget() in pdftranslator.cpp of PoDoFo 0.9.6, while creating the PdfXObject, as demonstrated by podofoimpose. It allows an attacker to cause Denial of Service.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

debiandebian/libpodofo< libpodofo 0.9.6+dfsg-4 (bookworm)

Patches

🔴Vulnerability Details

2
GHSA
GHSA-qp6c-p26q-wjqf: A NULL pointer dereference vulnerability exists in the function PdfTranslator::setTarget() in pdftranslator2022-05-14
OSV
CVE-2018-19532: A NULL pointer dereference vulnerability exists in the function PdfTranslator::setTarget() in pdftranslator2018-11-26

📋Vendor Advisories

1
Debian
CVE-2018-19532: libpodofo - A NULL pointer dereference vulnerability exists in the function PdfTranslator::s...2018

💬Community

3
Bugzilla
CVE-2018-19532 podofo: NULL pointer dereference in PdfTranslator::setTarget() in pdftranslator.cpp [epel-all]2018-12-04
Bugzilla
CVE-2018-19532 podofo: NULL pointer dereference in PdfTranslator::setTarget() in pdftranslator.cpp2018-12-04
Bugzilla
CVE-2018-19532 podofo: NULL pointer dereference in PdfTranslator::setTarget() in pdftranslator.cpp [fedora-all]2018-12-04
CVE-2018-19532 — NULL Pointer Dereference | cvebase