CVE-2018-8002

In PoDoFo 0.9.5, there exists an infinite loop vulnerability in PdfParserObject::ParseFileComplete() in PdfParserObject.cpp which may result in stack overflow. Remote attackers could leverage this vulnerability to cause a denial-of-service or possibly unspecified other impact via a crafted pdf file.
Infinite Loop
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 94.36%
Affected Products (NVD)
VendorProductVersion
podofo_projectpodofo
0.9.5
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libpodofo
bookworm
no-dsa
bullseye
no-dsa
buster
no-dsa
jessie
no-dsa
sid
vulnerable
stretch
no-dsa
trixie
vulnerable
wheezy
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libpodofo
artful
ignored
bionic
Fixed 0.9.5-9ubuntu0.1~esm1
released
cosmic
ignored
disco
ignored
eoan
ignored
focal
Fixed 0.9.6+dfsg-5ubuntu0.1~esm1
released
groovy
ignored
hirsute
ignored
impish
ignored
jammy
Fixed 0.9.7+dfsg-3ubuntu0.1~esm1
released
kinetic
ignored
lunar
ignored
mantic
ignored
noble
not-affected
oracular
not-affected
plucky
not-affected
questing
not-affected
resolute
not-affected
trusty
not-affected
xenial
Fixed 0.9.3-4ubuntu0.1~esm1
released