Heap-Based Buffer Over-read Vulnerability in PoDoFo by Artifex Software
CVE-2018-8001
7.8HIGH
What is CVE-2018-8001?
In PoDoFo version 0.9.5, a heap-based buffer over-read vulnerability exists in the UnescapeName() function located in PdfName.cpp. This flaw can be exploited by attackers remotely using specially crafted PDF files. Successful exploitation may lead to denial-of-service attacks or potentially other impacts that affect the integrity and availability of services utilizing the PoDoFo library.
