CVE-2018-20797Improper Restriction of Operations within the Bounds of a Memory Buffer in Project Podofo

Severity
6.5MEDIUMNVD
OSV7.8
EPSS
0.2%
top 63.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 27
Latest updateJan 20

Description

An issue was discovered in PoDoFo 0.9.6. There is an attempted excessive memory allocation in PoDoFo::podofo_calloc in base/PdfMemoryManagement.cpp when called from PoDoFo::PdfPredictorDecoder::PdfPredictorDecoder in base/PdfFiltersPrivate.cpp.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

🔴Vulnerability Details

3
OSV
libpodofo vulnerabilities2025-01-20
GHSA
GHSA-f2r9-m844-g6h4: An issue was discovered in PoDoFo 02022-05-14
OSV
CVE-2018-20797: An issue was discovered in PoDoFo 02019-02-27

📋Vendor Advisories

2
Ubuntu
PoDoFo library vulnerabilities2025-01-20
Debian
CVE-2018-20797: libpodofo - An issue was discovered in PoDoFo 0.9.6. There is an attempted excessive memory ...2018

💬Community

3
Bugzilla
CVE-2018-20797 podofo: excessive memory allocation in PoDoFo::podofo_calloc in base/PdfMemoryManagement.cpp [fedora-all]2019-02-28
Bugzilla
CVE-2018-20797 podofo: excessive memory allocation in PoDoFo::podofo_calloc in base/PdfMemoryManagement.cpp2019-02-28
Bugzilla
CVE-2018-20797 podofo: excessive memory allocation in PoDoFo::podofo_calloc in base/PdfMemoryManagement.cpp [epel-all]2019-02-28
CVE-2018-20797 — Podofo Project Podofo vulnerability | cvebase