Heap Use-After-Free Vulnerability in PoDoFo Product by Podofo
CVE-2023-31566
8.8HIGH
What is CVE-2023-31566?
The PoDoFo library version 0.10.0 is susceptible to a heap use-after-free flaw originating from the function PoDoFo::PdfEncrypt::IsMetadataEncrypted(). This vulnerability may lead to potential exploitation, allowing attackers to manipulate memory, which can result in arbitrary code execution or other unintended behavior. Users and developers are advised to review the library's usage and consider upgrades or patches to mitigate the risk associated with this vulnerability.
