Heap-Based Buffer Overflow in PoDoFo PDF Processing Tool
CVE-2019-9687
9.8CRITICAL
What is CVE-2019-9687?
The PoDoFo PDF processing library version 0.9.6 contains a heap-based buffer overflow vulnerability in the function PdfString::ConvertUTF16toUTF8 located in base/PdfString.cpp. This flaw may allow attackers to exploit memory corruption, potentially leading to arbitrary code execution or denial of service in applications that utilize this library. Users are advised to review the issue and apply necessary patches to ensure security.
