NULL pointer dereference in podofo and Fedora - CVE-2019-9199
Published: February 27, 2019 / Updated: August 8, 2020
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error in pdftranslator.cpp in PoDoFo 0.9.6 has a NULL pointer dereference that can (for example) be triggered by sending a crafted PDF file to the podofoimpose binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. A remote attacker can perform a denial of service (DoS) attack.
Affected software
Fedora
Arch Linux
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Micro
SUSE Package Hub 15
openSUSE Leap
podofo (Alpine package)
podofo
mingw-podofo
libpodofo0_9_6-debuginfo
libpodofo0_9_6
libpodofo-devel
podofo-debuginfo
podofo-debugsource
How to mitigate CVE-2019-9199
podofo - addressed in versions 0.9.6-6.fc29, 0.9.6-6.fc30
mingw-podofo - addressed in versions 0.9.6-8.fc29, 0.9.6-8.fc30
libpodofo0_9_6-debuginfo - update to 0.9.6-150300.3.9.1
libpodofo0_9_6 - update to 0.9.6-150300.3.9.1
libpodofo-devel - update to 0.9.6-150300.3.9.1
podofo - update to 0.9.6-150300.3.9.1
podofo-debuginfo - update to 0.9.6-150300.3.9.1
podofo-debugsource - update to 0.9.6-150300.3.9.1
External References
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CIC2EXSSMBT3MY2HY42IIY4BUQS2SVYB/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NTJ5AAM6Y4NMSELEH7N5ZG4DNO56BCYF/
- https://research.loginsoft.com/bugs/null-pointer-dereference-vulnerability-in-setsource-podofo-0-9-6-trunk-r1967/
- https://sourceforge.net/p/podofo/tickets/40/