Excessive Memory Allocation Vulnerability in PoDoFo by PoDoFo Team
CVE-2018-20797

6.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
27 February 2019

What is CVE-2018-20797?

A critical issue has been identified in PoDoFo version 0.9.6 that results in excessive memory allocation during the execution of specific functions. This vulnerability occurs within the PdfMemoryManagement component when it attempts to allocate memory through the podofo_calloc function, which is called by the PdfPredictorDecoder. If exploited, this could potentially lead to performance degradation or application crashes due to resource exhaustion.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.