PT-2026-95146 · Podofo · Podofo
CVSS v4.0
6.9
Medium
| Vector | AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
PoDoFo versions 1.0.0 through 1.1.0
Description
Processing a crafted PDF containing an Indexed color-space image can lead to a heap out-of-bounds read. This occurs because the
PODOFO INVARIANT macro does not perform a runtime check, allowing a pixel index greater than or equal to m MapSize to access memory beyond m lookup within the PdfColorSpaceFilterIndexed::FetchScanLine() function. Additionally, the PdfColorSpaceFilterFactory::TryCreateFromObject() function uses an incorrect conjunction and lacks an upper bound when validating hival, which permits malformed Indexed color-space metadata. This flaw can result in the disclosure of adjacent heap data or cause the application to crash.Recommendations
Update to version 1.1.1.
Exploit
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Podofo