The function TextExtractor::ExtractText in TextExtractor.cpp:77 in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PDF document.
The product dereferences a pointer that it expects to be valid but is NULL.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/97980 | vdb entry third party advisory |
https://icepng.github.io/2017/04/21/PoDoFo-1/ | third party advisory exploit |
https://github.com/icepng/PoC/tree/master/PoC1 | third party advisory |