CVE-2019-9199

HIGH

PoDoFo 0.9.6 - Denial of Service via NULL Pointer Dereference in PdfTranslator

Title source: llm
STIX 2.1

Description

PoDoFo::Impose::PdfTranslator::setSource() in pdftranslator.cpp in PoDoFo 0.9.6 has a NULL pointer dereference that can (for example) be triggered by sending a crafted PDF file to the podofoimpose binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.

Scores

CVSS v3 8.8
EPSS 0.0255
EPSS Percentile 83.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-476
Status published
Products (3)
fedoraproject/fedora 29
fedoraproject/fedora 30
podofo_project/podofo 0.9.6
Published Feb 26, 2019
Tracked Since Feb 18, 2026