Vulnerabilities > CVE-2018-8002 - Infinite Loop vulnerability in Podofo Project Podofo 0.9.5

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
podofo-project
CWE-835
exploit available

Summary

In PoDoFo 0.9.5, there exists an infinite loop vulnerability in PdfParserObject::ParseFileComplete() in PdfParserObject.cpp which may result in stack overflow. Remote attackers could leverage this vulnerability to cause a denial-of-service or possibly unspecified other impact via a crafted pdf file.

Vulnerable Configurations

Part Description Count
Application
Podofo_Project
1

Exploit-Db

descriptionPoDoFo 0.9.5 - Buffer Overflow. CVE-2018-8002. Dos exploit for Linux platform. Tags: Buffer Overflow
fileexploits/linux/dos/44946.txt
idEDB-ID:44946
last seen2018-06-26
modified2018-06-26
platformlinux
port
published2018-06-26
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/44946/
titlePoDoFo 0.9.5 - Buffer Overflow
typedos

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/148308/podofo095-overflow.txt
idPACKETSTORM:148308
last seen2018-06-27
published2018-06-26
reporterr4xis
sourcehttps://packetstormsecurity.com/files/148308/PoDoFo-0.9.5-Buffer-Overflow.html
titlePoDoFo 0.9.5 Buffer Overflow