CVE-2023-2241

Name
CVE-2023-2241
Description
A vulnerability, which was classified as critical, was found in PoDoFo 0.10.0. Affected is the function readXRefStreamEntry of the file PdfXRefStreamParserObject.cpp. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The name of the patch is 535a786f124b739e3c857529cecc29e4eeb79778. It is recommended to apply a patch to fix this issue. VDB-227226 is the identifier assigned to this vulnerability.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://vuldb.com/?ctiid.227226
MISC https://github.com/podofo/podofo/issues/69
MISC https://github.com/podofo/podofo/commit/535a786f124b739e3c857529cecc29e4eeb79778
MISC https://vuldb.com/?id.227226
MISC https://github.com/podofo/podofo/files/11260976/poc-file.zip

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:podofo_project:podofo:0.10.0:*:*:*:*:*:*:* podofo == None == 0.10.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
podofo edge-community 0.10.0-r0 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable