Heap-based Buffer Overflow in PoDoFo Affects Multiple Versions
CVE-2018-8000
8.8HIGH
What is CVE-2018-8000?
PoDoFo 0.9.5 contains a heap-based buffer overflow vulnerability in the PdfTokenizer::GetNextToken() function. This flaw allows remote attackers to craft malicious PDF files that can cause denial-of-service attacks or potentially enable arbitrary code execution. This vulnerability is related to a prior issue identified in CVE-2017-5886.
