PT-2025-34570 · Podofo+1 · Podofo+1

·

CVE-2025-9394

·

Published

2025-08-24

·

Updated

2025-09-12

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: PoDoFo version 1.1.0-dev
Description: A flaw has been identified in the PDF Dictionary Parser component of PoDoFo. The issue resides within the PdfTokenizer::DetermineDataType function in the file src/podofo/main/PdfTokenizer.cpp. Manipulation of the affected component can lead to a use-after-free condition, potentially allowing for local exploitation. The exploit for this issue has been published.
Recommendations: Apply the patch 22d16cb142f293bf956f66a4d399cdd65576d36c to remediate this issue.

Exploit

Fix

Use After Free

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-9394

Affected Products

Debian
Podofo