oss-sec mailing list archives

Re: podofo: NULL pointer dereference in PoDoFo::PdfParser::ReadXRefSubsection (PdfParser.cpp)


From: <cve-assign () mitre org>
Date: Thu, 2 Feb 2017 01:10:01 -0500

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

https://blogs.gentoo.org/ago/2017/02/01/podofo-null-pointer-dereference-in-podofopdfparserreadxrefsubsection-pdfparser-cpp
AddressSanitizer: SEGV on unknown address 0x0000000000d8
podofo-0.9.4/src/base/PdfParser.cpp:772

Use CVE-2017-5855.

- -- 
CVE Assignment Team
M/S M300, 202 Burlington Road, Bedford, MA 01730 USA
[ A PGP key is available for encrypted communications at
  http://cve.mitre.org/cve/request_id.html ]
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCAAGBQJYkscsAAoJEHb/MwWLVhi20V4P/RspGoWe2F1kbNHTP1GrHFq1
EqHsL9aI3gBcVb2fpkdDspdOeoBFOdIv7E1ua5AMRb6uhBc1SFNiMHt/cHRKYPHu
GQz/Ju9UkhTplmU2jZCAA+p5hV68fI0q6quF5vW7nMCPGJNVihZRfu4E9vr3AEoi
vxT1vRDPoHxVAKLdxTBlCSkWAbTTzL4OnaMR7c7GQY3X//EqwGKINLYrsThs17pN
lmYqsTgDM/P61dngmmkjo9NUtd36QqxXlLQbdKTerXugnnY7QreNbxENtGjo+jN0
Ia98dTVQ1+vBTzhN26wgxx+rufNxX9t47e8u1c8zG+aY4skrnpb3Lb3rGFosWpCO
s//lch5e0rk9pCuH/qm21HaAICt56XTv9Iuw4jjMaXSKsceyigR6ZUnWnd8lD/UQ
7Y9XW8ZS2FaP1y4SPT0a5tusf4t48+9MfZq1Xc/b+mwhE2Og4Jn/J9f9qBogMZDN
eK9vqWxchU7nv1ZwA+dML3VhSMOqoeHMWUA3AwuoowFZLco4HlKvigSo/+/QrE+A
iuCnbuz/uZAdsV3GuqR5CRr8lIxZ06vbQ8eUqCZg0CuhFrHsbvu4+NCoP9hs4yRg
k810ls3MQabMNbX+aF+fqfsWo4/i3wSOjrjm6lvipXEjvXtgGvRnyz9L0S3AHptK
wgLZyQc7yKFA5c0BeYn3
=4jw5
-----END PGP SIGNATURE-----


Current thread: