CVE-2019-20093 — NULL Pointer Dereference in Project Podofo
Severity
5.5MEDIUMNVD
EPSS
0.5%
top 35.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 30
Latest updateMay 24
Description
The PoDoFo::PdfVariant::DelayedLoad function in PdfVariant.h in PoDoFo 0.9.6 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file, because of ImageExtractor.cpp.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6
Affected Packages2 packages
Also affects: Fedora 30, 31
🔴Vulnerability Details
2📋Vendor Advisories
1Debian▶
CVE-2019-20093: libpodofo - The PoDoFo::PdfVariant::DelayedLoad function in PdfVariant.h in PoDoFo 0.9.6 all...↗2019
💬Community
5Bugzilla▶
CVE-2019-20093 podofo: NULL pointer dereference in PoDoFo::PdfVariant::DelayedLoad in PdfVariant.h [epel-6]↗2020-01-17
Bugzilla▶
CVE-2019-20093 podofo: NULL pointer dereference in PoDoFo::PdfVariant::DelayedLoad in PdfVariant.h [epel-7]↗2020-01-17
Bugzilla▶
CVE-2019-20093 podofo: NULL pointer dereference in PoDoFo::PdfVariant::DelayedLoad in PdfVariant.h↗2020-01-17
Bugzilla▶
CVE-2019-20093 podofo: NULL pointer dereference in PoDoFo::PdfVariant::DelayedLoad in PdfVariant.h [fedora-all]↗2020-01-17
Bugzilla▶
CVE-2019-20093 mingw-podofo: podofo: NULL pointer dereference in PoDoFo::PdfVariant::DelayedLoad in PdfVariant.h [fedora-all]↗2020-01-17