Bugzilla – Bug 1029858
VUL-0: CVE-2017-6848: podofo: The PoDoFo::PdfXObject::PdfXObject function in PdfXObject.cpp in PoDoFo 0.9.5allows remote attacker...
Last modified: 2022-04-19 10:36:03 UTC
CVE-2017-6848 The PoDoFo::PdfXObject::PdfXObject function in PdfXObject.cpp in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-6848 http://seclists.org/oss-sec/2017/q1/602 http://people.canonical.com/~ubuntu-security/cve/2017/CVE-2017-6848.html http://www.cvedetails.com/cve/CVE-2017-6848/ http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-6848 https://blogs.gentoo.org/ago/2017/03/02/podofo-null-pointer-dereference-in-podofopdfxobjectpdfxobject-pdfxobject-cpp/
Please submit for this. Thank you
*** Bug 1027777 has been marked as a duplicate of this bug. ***
Upstream commit: - http://sourceforge.net/p/podofo/code/1846 This was fixed together with bsc#1027778 / CVE-2017-6847, but not mentioned inside the changes file. References: https://security-tracker.debian.org/tracker/CVE-2017-6847 https://security-tracker.debian.org/tracker/CVE-2017-6848 (We will keep this bug open until the changes file reference is fixed.)