NULL Pointer Dereference Vulnerability in PoDoFo 0.9.6's PdfTranslator::setSource() Function

NULL Pointer Dereference Vulnerability in PoDoFo 0.9.6's PdfTranslator::setSource() Function

CVE-2019-9199 · MEDIUM Severity

AV:N/AC:M/AU:N/C:P/I:P/A:P

PoDoFo::Impose::PdfTranslator::setSource() in pdftranslator.cpp in PoDoFo 0.9.6 has a NULL pointer dereference that can (for example) be triggered by sending a crafted PDF file to the podofoimpose binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.

Learn more about our Web Application Penetration Testing UK.