CVE-2019-9199
HIGHPoDoFo 0.9.6 - Denial of Service via NULL Pointer Dereference in PdfTranslator
Title source: llmDescription
PoDoFo::Impose::PdfTranslator::setSource() in pdftranslator.cpp in PoDoFo 0.9.6 has a NULL pointer dereference that can (for example) be triggered by sending a crafted PDF file to the podofoimpose binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.
References (6)
Core 6
Core References
Mailing List, Third Party Advisory vendor-advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NTJ5AAM6Y4NMSELEH7N5ZG4DNO56BCYF/
Mailing List, Third Party Advisory vendor-advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CIC2EXSSMBT3MY2HY42IIY4BUQS2SVYB/
Exploit, Third Party Advisory
https://research.loginsoft.com/bugs/null-pointer-dereference-vulnerability-in-setsource-podofo-0-9-6-trunk-r1967/
Exploit, Third Party Advisory
https://sourceforge.net/p/podofo/tickets/40/
Scores
CVSS v3
8.8
EPSS
0.0255
EPSS Percentile
83.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
CWE
CWE-476
Status
published
Products (3)
fedoraproject/fedora
29
fedoraproject/fedora
30
podofo_project/podofo
0.9.6
Published
Feb 26, 2019
Tracked Since
Feb 18, 2026