NULL pointer dereference in podofo and Fedora - CVE-2019-9199

 

NULL pointer dereference in podofo and Fedora - CVE-2019-9199

Published: February 27, 2019 / Updated: August 8, 2020


Vulnerability identifier: #VU36101
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-9199
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a NULL pointer dereference error in pdftranslator.cpp in PoDoFo 0.9.6 has a NULL pointer dereference that can (for example) be triggered by sending a crafted PDF file to the podofoimpose binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact. A remote attacker can perform a denial of service (DoS) attack.


Affected software

podofo
Fedora
Arch Linux
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Micro
SUSE Package Hub 15
openSUSE Leap
podofo (Alpine package)
podofo
mingw-podofo
libpodofo0_9_6-debuginfo
libpodofo0_9_6
libpodofo-devel
podofo-debuginfo
podofo-debugsource

How to mitigate CVE-2019-9199

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

podofo (Alpine package) - update to 0.9.7-r0
podofo - addressed in versions 0.9.6-6.fc29, 0.9.6-6.fc30
mingw-podofo - addressed in versions 0.9.6-8.fc29, 0.9.6-8.fc30
libpodofo0_9_6-debuginfo - update to 0.9.6-150300.3.9.1
libpodofo0_9_6 - update to 0.9.6-150300.3.9.1
libpodofo-devel - update to 0.9.6-150300.3.9.1
podofo - update to 0.9.6-150300.3.9.1
podofo-debuginfo - update to 0.9.6-150300.3.9.1
podofo-debugsource - update to 0.9.6-150300.3.9.1

External References

Related Security Bulletins