NULL Pointer Dereference Vulnerability in PoDoFo 0.9.6's PdfTranslator::setSource() Function
CVE-2019-9199 · MEDIUM Severity
AV:N/AC:M/AU:N/C:P/I:P/A:P
PoDoFo::Impose::PdfTranslator::setSource() in pdftranslator.cpp in PoDoFo 0.9.6 has a NULL pointer dereference that can (for example) be triggered by sending a crafted PDF file to the podofoimpose binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.
Learn more about our Web Application Penetration Testing UK.