Bug 1029858 - (CVE-2017-6848) VUL-0: CVE-2017-6848: podofo: The PoDoFo::PdfXObject::PdfXObject function in PdfXObject.cpp in PoDoFo 0.9.5allows remote attacker...
(CVE-2017-6848)
VUL-0: CVE-2017-6848: podofo: The PoDoFo::PdfXObject::PdfXObject function in ...
Status: NEW
: 1027777 (view as bug list)
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Antonio Larrosa
Security Team bot
https://smash.suse.de/issue/181629/
CVSSv3:NVD:CVE-2017-6848:5.5:(AV:L/AC...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2017-03-17 10:09 UTC by Victor Pereira
Modified: 2022-04-19 10:36 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 1 Johannes Segitz 2018-10-11 08:25:31 UTC
Please submit for this. Thank you
Comment 2 Alexandros Toptsoglou 2019-02-28 15:41:54 UTC
*** Bug 1027777 has been marked as a duplicate of this bug. ***
Comment 3 Alexander Bergmann 2022-04-19 10:36:03 UTC
Upstream commit:
- http://sourceforge.net/p/podofo/code/1846

This was fixed together with bsc#1027778 / CVE-2017-6847, but not mentioned inside the changes file.

References:
https://security-tracker.debian.org/tracker/CVE-2017-6847
https://security-tracker.debian.org/tracker/CVE-2017-6848

(We will keep this bug open until the changes file reference is fixed.)