Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2018-8002Infinite Loop in Project Podofo

CWE-835Infinite Loop10 documents7 sources
Severity
8.8HIGHNVD
OSV7.8
EPSS
5.6%
top 9.69%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedMar 9
Latest updateJan 20

Description

In PoDoFo 0.9.5, there exists an infinite loop vulnerability in PdfParserObject::ParseFileComplete() in PdfParserObject.cpp which may result in stack overflow. Remote attackers could leverage this vulnerability to cause a denial-of-service or possibly unspecified other impact via a crafted pdf file.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

debiandebian/libpodofo< libpodofo 0.9.8+dfsg-1 (bookworm)

🔴Vulnerability Details

3
OSV
libpodofo vulnerabilities2025-01-20
GHSA
GHSA-7p4w-p3xm-vgfq: In PoDoFo 02022-05-13
OSV
CVE-2018-8002: In PoDoFo 02018-03-09

💥Exploits & PoCs

1
Exploit-DB
PoDoFo 0.9.5 - Buffer Overflow (PoC)2018-06-26

📋Vendor Advisories

2
Ubuntu
PoDoFo library vulnerabilities2025-01-20
Debian
CVE-2018-8002: libpodofo - In PoDoFo 0.9.5, there exists an infinite loop vulnerability in PdfParserObject:...2018

💬Community

3
Bugzilla
CVE-2018-8000 CVE-2018-8001 CVE-2018-8002 podofo: various flaws [epel-all]2018-03-12
Bugzilla
CVE-2018-8002 podofo [fedora-all]2018-03-12
Bugzilla
CVE-2018-8002 podofo: infinite loop in PdfParserObject::ParseFileComplete() in PdfParserObject.cpp2018-03-12
CVE-2018-8002 — Infinite Loop in Podofo Project Podofo | cvebase