VDB

CVE-2018-14320

CVE-2018-14320 PUBLISHED

This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of PoDoFo. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within PdfEncoding::ParseToUnicode. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-5673.

EPSS 0.50% · 66.2th percentile

Risk Scores

EPSS Score
0.50%
66.2th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:18.04:LTSlibpodofo0.9.5-8, 0.9.5-8build1, 0.9.5-9
Ubuntu:Pro:16.04:LTSlibpodofo0.9.3-3, 0.9.3-4ubuntu0.1~esm1, 0.9.0-1.3
Ubuntu:Pro:14.04:LTSlibpodofo0, 0.9.0-1.1ubuntu1, 0.9.0-1.2ubuntu0.1~esm1

Timeline

  • Sep 17, 2018 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 22, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Oct 25, 2021 EPSS Score
  • Dec 27, 2021 EPSS Score
  • Feb 27, 2022 EPSS Score
  • May 1, 2022 EPSS Score
  • Jul 2, 2022 EPSS Score
  • Nov 5, 2022 EPSS Score
  • Jan 7, 2023 EPSS Score
  • Mar 10, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›